77.88.21.249 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 77.88.21.249 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 30/100

Host and Network Information

  • Tags: awsindia, cyber security, ioc, malicious, Nextray, ntp, phishing, scanners, tsec

  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: stopforumspam_365d

  • Country: Russia
  • Network: AS208722 yandex oy
  • Noticed: 1 times
  • Protcols Attacked: ntp
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, India, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: mx2.yandex.ru www.edegarmentandtextile.com agentmaster.ru crcmodels.com.br wittmann.su birinsan.com.tr elbiyazilim.com mx1.yandex.ru www.phoenix2011.com.ua moonie.app artiisg.com haokaikai.cn bmwaksesuar.com educatech.xyz liga-optimorum.com senmux.com capitalaccounting.ru mx.yandex.ru mx.yandex.net

Malware Detected on Host

Count: 8 a98ec2411ceb38e591c1b586cd51027fe3fe1d214b4fb8f341df0af3b13d7da1 653e4374b0c1b6732d1c2090856d15219c697ad5c8febe52a856306ed535162d 3ee74ff31dc92de4d079fb4fd34aae0eafaf4a604920b7b22f3c1b9235f26e03 bf73b95369373612b1305e87eb1eae5471709772b70f82396f7e47fad41e8d0f a3bf8483cdc90d95b841d548c5f5c2c6aa6f49531d667156273eb72f196d3630 89536af43e3b24593a18f30fd060cc8f165dd27b8424a881c7589b217d3e746b e920451b2cb2a265493f1490d40e18dde97b30842a704c693538b3622597c428 39312ee70141c6a5ce5a3e648ad40be2acea224363ff596f2f8dcb150af622aa

Open Ports Detected

25

Map

Whois Information

  • inetnum: 77.88.21.0 - 77.88.21.255
  • netname: YANDEX-77-88-21
  • status: ASSIGNED PA
  • country: RU
  • descr: Yandex enterprise network
  • admin-c: YNDX1-RIPE
  • tech-c: YNDX1-RIPE
  • org: ORG-YA1-RIPE
  • mnt-by: YANDEX-MNT
  • created: 2007-09-24T16:18:59Z
  • last-modified: 2022-04-05T15:29:34Z
  • organisation: ORG-YA1-RIPE
  • org-name: YANDEX LLC
  • country: RU
  • org-type: LIR
  • address: LVA TOLSTOY STREET, 16
  • address: 119021
  • address: Moscow
  • address: RUSSIAN FEDERATION
  • phone: +74957397000
  • fax-no: +74957397070
  • admin-c: MK24579-RIPE
  • admin-c: AUR2-RIPE
  • admin-c: EM3673-RIPE
  • abuse-c: YAH6-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: YANDEX-MNT
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: YANDEX-MNT
  • created: 2004-04-22T14:39:02Z
  • last-modified: 2023-07-17T08:05:45Z
  • role: Yandex LLC Network Operations
  • address: Yandex LLC
  • address: 16, Leo Tolstoy St.
  • address: 119021
  • address: Moscow
  • address: Russian Federation
  • phone: +7 495 739 7000
  • fax-no: +7 495 739 7070
  • admin-c: MK24579-RIPE
  • tech-c: EM3673-RIPE
  • tech-c: AUR2-RIPE
  • nic-hdl: YNDX1-RIPE
  • mnt-by: YANDEX-MNT
  • created: 2002-06-07T05:35:50Z
  • last-modified: 2021-08-23T16:42:06Z
  • abuse-mailbox: [email protected]
  • route: 77.88.0.0/18
  • descr: Yandex enterprise network
  • origin: AS13238
  • mnt-by: YANDEX-MNT
  • created: 2007-03-15T11:01:41Z
  • last-modified: 2007-03-15T11:01:41Z

Links to attack logs

awsindia-ntp-bruteforce-ip-list-2022-03-20 ** ** **