61.166.225.54 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 61.166.225.54 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: China
  • Network: AS4134 chinanet
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy

Open Ports Detected

100 10000 10001 10134 102 1024 10243 10250 1027 104 10443 10554 1099 11 110 11000 111 11112 11210 11211 113 11371 1153 1177 119 1200 122 1234 12345 13 1311 1337 13579 1400 14147 14265 1433 14344 1471 15 1515 1521 1599 16010 16030 1604 161 16992 16993 17 17000 1723 1741 179 1800 1801 18081 18245 1883 19071 1911 1925 1935 195 199 2000 2002 2008 20256 2053 20547 2067 2082 2083 2086 2087 21 21025 2121 2150 2154 2181 22 2201 221 2222 23 23023 2323 2332 23424 2345 2375 2376 2404 2455 2480 25 25001 2552 25565 2559 2561 26 27015 27017 2761 2762 28015 3000 30003 3001 3005 3050 3056 3072 3075 3076 3077 3087 3089 3096 3112 31337 3200 32400 3260 3268 3269 32764 3299 3301 33060 3310 3388 3389 3406 3460 35000 3524 3541 3542 3551 3555 3563 3566 3689 37 37215 3749 37777 3780 389 3950 4000 4022 4040 4063 4064 4157 41800 427 4282 43 4321 4369 44158 4430 444 4443 448 4500 4505 4506 4523 4545 4664 4786 47990 4840 4848 4899 49 49152 49153 4949 500 5000 50000 5001 5005 50050 5007 50070 5009 5010 50100 502 5025 515 5172 5201 5222 52288 5269 52869 53 5357 5400 54138 5431 5432 5435 548 55000 554 55442 55443 5555 55554 55580 5560 5605 5672 56981 5800 5801 5853 5858 587 5901 5910 5938 59417 5984 5985 5986 6000 60001 6001 6002 60030 6010 60129 6080 61613 61616 62078 631 6352 6443 6511 6653 666 6664 6666 6668 6697 70 7001 7017 7071 7171 7218 7415 7443 7548 7634 7657 771 7776 7777 7779 789 79 7989 8000 8001 8008 8009 801 8010 8012 8024 8025 8038 8060 8069 8081 8083 8085 8086 8087 8098 81 8105 8123 8126 8139 8140 8181 82 8200 8252 8291 8333 8334 8383 84 8408 8409 8422 8424 843 8432 8443 8447 8500 8545 8554 8575 8590 8623 8700 8728 88 8809 8813 8819 8821 8828 8834 8838 8844 8868 8870 8880 8888 8889 8991 9000 9001 9002 9009 9013 9016 902 9032 9080 9090 9091 9092 9095 9099 9100 9109 9110 9151 9160 9189 9191 9212 9218 9295 9300 9306 9418 943 9443 9500 9530 9595 9600 9633 9761 9765 9800 990 992 9943 9944 9981 999 9998 9999

CVEs Detected

CVE-2012-6708 CVE-2015-9251 CVE-2019-11358 CVE-2020-11022 CVE-2020-11023 CVE-2020-23064

Map

Whois Information

  • inetnum: 61.166.0.0 - 61.166.255.255
  • netname: CHINANET-YN
  • country: CN
  • descr: CHINANET Yunnan province network
  • admin-c: ZL48-AP
  • tech-c: ZL48-AP
  • status: ALLOCATED NON-PORTABLE
  • mnt-by: MAINT-CHINANET
  • last-modified: 2008-09-04T06:49:46Z
  • person: zhiyong liu
  • nic-hdl: ZL48-AP
  • e-mail: [email protected]
  • address: 136 beijin roadkunmingchina
  • phone: +86-871-68226585
  • fax-no: +86-871-8221536
  • country: CN
  • mnt-by: MAINT-CHINANET-YN
  • last-modified: 2018-12-27T01:58:34Z

Links to attack logs

anonymous-proxy-ip-list-2023-10-27