79.137.196.4 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 43/100

Host and Network Information

  • Tags: Brute-Force, Bruteforce, SSH, digital ocean, scanners, ssh
  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS12695 llc digital network
  • Noticed: 3 times
  • Protcols Attacked: ssh
  • Countries Attacked: Germany
  • Passive DNS Results: newest-games.app ukrsupport.info consulting-ukraine.tk

Open Ports Detected

1000 102 1026 104 10554 11 110 1110 11112 11210 113 1200 12000 121 1234 13 131 1311 135 1366 14147 1433 1494 15 1521 1604 175 18245 1830 1883 1935 1990 2006 2020 2022 20256 2053 2056 2069 2081 2087 21 21025 2111 2121 21379 2181 22 2201 2202 221 2221 2222 2266 2382 2404 2480 25001 2548 2553 2557 2559 2566 2568 2569 27017 2761 28015 3001 3002 3048 3051 3055 3059 3072 3073 3076 3080 3082 3086 3093 3107 3115 3260 33060 3310 3333 3388 3401 3404 3407 35000 3524 3556 3559 3566 3567 3689 37777 389 3950 4000 4022 4042 4064 4117 41800 4242 427 4282 43 4321 44158 4444 445 44818 449 4506 4523 465 4734 4786 4911 49152 49153 4949 5007 5009 5060 5090 515 5150 5222 5269 5280 5321 54138 5432 548 55000 555 5555 55554 5591 5593 5604 5608 5672 5801 5858 587 5906 5907 5910 5938 6001 6002 6003 6009 61613 61616 636 6379 646 6511 6565 6653 6666 6667 6668 70 7000 7004 7070 7444 7445 7634 7776 7887 80 800 8005 801 8016 8017 8022 8032 8036 8040 8042 805 8051 808 8085 8086 8089 8098 8105 8107 8126 8140 82 8200 8282 8291 8383 8408 8416 8420 8426 8444 85 8513 8545 8554 8585 8586 8602 8622 8623 8649 8686 8728 873 8767 8779 8790 8802 8805 8812 8821 8833 8847 8852 8854 8864 8865 8866 8878 888 8887 8889 8935 9000 9004 9005 9008 9014 9030 9031 9032 9036 9042 9045 9051 9089 9101 9102 9109 9110 9119 9151 9160 9189 9199 9205 9206 9216 9219 9251 9302 9306 9310 9418 9444 9527 9530 97 9761 9765 98 9861 9876 99 9944 9950 9955 9966 9991 9998

CVEs Detected

CVE-2006-20001 CVE-2019-0196 CVE-2019-0197 CVE-2019-0211 CVE-2019-0215 CVE-2019-0217 CVE-2019-0220 CVE-2019-10081 CVE-2019-10082 CVE-2019-10092 CVE-2019-10097 CVE-2019-10098 CVE-2019-17567 CVE-2019-9517 CVE-2020-11984 CVE-2020-11993 CVE-2020-13938 CVE-2020-1927 CVE-2020-1934 CVE-2020-35452 CVE-2020-9490 CVE-2021-26690 CVE-2021-26691 CVE-2021-33193 CVE-2021-34798 CVE-2021-36160 CVE-2021-39275 CVE-2021-40438 CVE-2021-44224 CVE-2021-44790 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-23943 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436 CVE-2023-25690 CVE-2023-27522

Map

Whois Information

  • inetnum: 79.137.196.0 - 79.137.199.255
  • netname: aeza-net-7
  • country: NL
  • geofeed: https://aeza.net/static/ipv4_f.csv
  • geoloc: 52.3559446 4.9531184
  • org: ORG-AGL38-RIPE
  • mnt-routes: aeza-mnt
  • mnt-domains: aeza-mnt
  • admin-c: AN32749-RIPE
  • tech-c: AN32749-RIPE
  • status: ASSIGNED PA
  • mnt-by: DN-MNT
  • created: 2022-09-01T13:10:46Z
  • last-modified: 2023-02-27T08:09:03Z
  • organisation: ORG-AGL38-RIPE
  • org-name: AEZA GROUP LLC
  • org-type: OTHER
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • abuse-c: AA38875-RIPE
  • mnt-ref: aeza-mnt
  • mnt-ref: DN-MNT
  • mnt-ref: VF1-MNT
  • mnt-ref: DATAMAX-M
  • mnt-by: aeza-mnt
  • created: 2021-11-23T13:59:30Z
  • last-modified: 2023-01-06T12:18:43Z
  • role: Aeza Network
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • nic-hdl: AN32749-RIPE
  • mnt-by: aeza-group-mnt
  • created: 2021-11-24T09:55:02Z
  • last-modified: 2021-11-24T09:55:02Z
  • route: 79.137.196.0/22
  • origin: AS210644
  • mnt-by: aeza-mnt
  • mnt-by: AEZA-NETWORK-MNT
  • created: 2022-09-01T23:02:07Z
  • last-modified: 2022-09-01T23:02:07Z

Links to attack logs

dofrank-ssh-bruteforce-ip-list-2023-05-04