65.109.231.57 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 65.109.231.57 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Germany
  • Network: AS24940 hetzner online gmbh
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy

Open Ports Detected

10001 10134 1024 10243 10554 1099 110 11000 11112 11210 11300 11371 1153 1177 1200 12000 1234 12345 1311 1355 13579 1400 14147 14265 143 1433 1471 1521 1599 1604 1650 16992 17000 1723 1741 1800 1801 18081 18245 1883 19000 19071 1911 1925 1935 1962 2000 20000 2001 2002 2006 2008 20256 2048 20547 2067 2069 2080 2081 2082 2086 2087 21 21025 2121 21379 2154 2181 22 2222 23 23023 2323 23424 2345 2375 2404 2455 2480 25 25001 25105 25565 2628 2650 27015 2761 2762 28015 28017 3000 30002 30003 3001 3050 3051 3060 3069 3075 3083 3086 3128 32400 3260 3268 3269 32764 3299 3301 3306 33060 3388 3389 3443 35000 3549 3551 3689 37215 3749 37777 389 4000 4022 4040 4063 4064 41800 4242 4243 4282 4321 4369 44158 443 4444 445 44818 4500 4506 4567 4664 4782 4786 4840 4848 4899 4911 49152 49153 4949 5000 50000 5005 50050 5007 50070 5009 5010 50100 5025 51106 51235 5172 5201 5222 5269 52869 53535 5357 54138 5432 5435 5443 55000 55442 55554 5560 5601 5603 5672 56981 5800 5801 5858 58749 5901 5938 59417 5984 5985 6000 60001 6001 6002 60030 60129 6080 61613 61616 62078 62765 6379 63914 6443 6543 6633 6653 6664 6666 6668 6697 7070 7171 7218 7415 7474 7535 7547 7657 7777 7779 7989 80 8000 8001 8008 8009 8010 8033 8060 8069 8080 8086 8087 8090 8098 8099 81 8102 8112 8123 8126 8200 8238 8291 8333 8334 8411 8447 8500 8545 8554 8575 8637 8649 8728 8800 8801 8859 8865 8872 8888 8988 9000 9002 9009 9011 9029 9033 9042 9051 9080 9090 9092 9100 9151 9160 9191 9203 9217 9295 9306 9418 9530 9595 9600 9633 9690 9761 9800 9869 9898 9944 9998 9999

CVEs Detected

CVE-2008-1446 CVE-2009-2521 CVE-2017-20005 CVE-2017-7529 CVE-2018-16843 CVE-2018-16844 CVE-2018-16845 CVE-2019-20372 CVE-2019-9511 CVE-2019-9513 CVE-2019-9516 CVE-2020-1938 CVE-2021-23017 CVE-2021-3618

Map

Whois Information

  • NetRange: 65.108.0.0 - 65.109.255.255
  • CIDR: 65.108.0.0/15
  • NetName: RIPE
  • NetHandle: NET-65-108-0-0-1
  • Parent: NET65 (NET-65-0-0-0-0)
  • NetType: Early Registrations, Transferred to RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 2021-06-22
  • Updated: 2021-06-22
  • Ref: https://rdap.arin.net/registry/ip/65.108.0.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • inetnum: 65.108.0.0 - 65.109.255.255
  • netname: DE-HETZNER-20010209
  • country: FI
  • org: ORG-HOA1-RIPE
  • admin-c: HOAC1-RIPE
  • tech-c: HOAC1-RIPE
  • status: ALLOCATED PA
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: HOS-GUN
  • mnt-lower: HOS-GUN
  • mnt-domains: HOS-GUN
  • mnt-routes: HOS-GUN
  • created: 2021-06-22T13:57:47Z
  • last-modified: 2021-09-01T09:31:32Z
  • organisation: ORG-HOA1-RIPE
  • org-name: Hetzner Online GmbH
  • country: DE
  • org-type: LIR
  • address: Industriestrasse 25
  • address: D-91710
  • address: Gunzenhausen
  • address: GERMANY
  • phone: +49 9831 5050
  • fax-no: +49 9831 5053
  • admin-c: MF1400-RIPE
  • admin-c: GM834-RIPE
  • admin-c: HOAC1-RIPE
  • admin-c: MH375-RIPE
  • admin-c: SK2374-RIPE
  • admin-c: SK8441-RIPE
  • abuse-c: HOAC1-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: HOS-GUN
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: HOS-GUN
  • created: 2004-04-17T11:07:58Z
  • last-modified: 2022-11-22T18:32:44Z
  • role: Hetzner Online GmbH - Contact Role
  • address: Hetzner Online GmbH
  • address: Industriestrasse 25
  • address: D-91710 Gunzenhausen
  • address: Germany
  • phone: +49 9831 505-0
  • fax-no: +49 9831 505-3
  • abuse-mailbox: [email protected]
  • org: ORG-HOA1-RIPE
  • admin-c: MH375-RIPE
  • tech-c: GM834-RIPE
  • tech-c: SK2374-RIPE
  • tech-c: MF1400-RIPE
  • tech-c: SK8441-RIPE
  • tech-c: DD15478-RIPE
  • nic-hdl: HOAC1-RIPE
  • mnt-by: HOS-GUN
  • created: 2004-08-12T09:40:20Z
  • last-modified: 2022-11-22T18:33:55Z
  • route: 65.109.0.0/16
  • org: ORG-HOA1-RIPE
  • descr: HETZNER-DC
  • origin: AS24940
  • mnt-by: HOS-GUN
  • created: 2021-06-25T09:20:18Z
  • last-modified: 2021-06-25T09:20:18Z
  • organisation: ORG-HOA1-RIPE
  • org-name: Hetzner Online GmbH
  • country: DE
  • org-type: LIR
  • address: Industriestrasse 25
  • address: D-91710
  • address: Gunzenhausen
  • address: GERMANY
  • phone: +49 9831 5050
  • fax-no: +49 9831 5053
  • admin-c: MF1400-RIPE
  • admin-c: GM834-RIPE
  • admin-c: HOAC1-RIPE
  • admin-c: MH375-RIPE
  • admin-c: SK2374-RIPE
  • admin-c: SK8441-RIPE
  • abuse-c: HOAC1-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: HOS-GUN
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: HOS-GUN
  • created: 2004-04-17T11:07:58Z
  • last-modified: 2022-11-22T18:32:44Z

Links to attack logs

anonymous-proxy-ip-list-2023-11-29