79.172.212.132 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Likely Malicious Host 🟠 55/100

Host and Network Information

  • Mitre ATT&CK IDs: T1059 - Command and Scripting Interpreter, T1105 - Ingress Tool Transfer, T1210 - Exploitation of Remote Services, T1218 - Signed Binary Proxy Execution, T1496 - Resource Hijacking, T1505 - Server Software Component, T1566 - Phishing
  • Tags: Botnet, Nextray, alpha strike, apache log4j, awsjap, blackberry, bruteforce, cia triad, cobalt strike, codi starks, command, company, contabo gmbh, cve201710271, cve20192725, cve202126084, cve20220543, cyber security, december, digitaloceanasn, domain, download, drupal, execution, file, file path, flaws, flood, fortune, hunter, hydra, indonesia, ioc, ioc type, ipaddress, ipport, juniper threat, labs, labs gmbh, level3, linode, log4u, malicious, malware, march, muhstik, muhstik gang, next, ognl, oracle fusion, oracle weblogic, ovh sas, phishing, ponynet, powershell, probing, prophet spider, rce attempt, redis, redis server, scanning, security llc, september, server rce, service, shell, strings, telecom, tmpruss, url http, webscan, webscanner bruteforce web app attack
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: ciarmy

  • Country: Hungary
  • Network: AS61998 szerverplex.hu kft.
  • Noticed: 50 times
  • Protcols Attacked: redis
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Japan, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.chefsperhour.co.uk chefsperhour.co.uk

Open Ports Detected

443 80

Map

Whois Information

  • inetnum: 79.172.212.0 - 79.172.212.255
  • netname: SZERVERPLEX
  • descr: SzerverPlex.hu Kft
  • descr: 5475 Csepa Jokai utca 21.
  • country: HU
  • admin-c: ZV41-RIPE
  • tech-c: ZV41-RIPE
  • status: ASSIGNED PA
  • mnt-by: DENINET-MNT
  • created: 2008-06-25T18:39:06Z
  • last-modified: 2014-08-03T09:25:05Z
  • person: Zoltan Virag
  • address: H-1132 Budapest, Victor Hugo u. 18-22.
  • address: HU
  • phone: +3612960075
  • fax-no: +3612960076
  • nic-hdl: ZV41-RIPE
  • mnt-by: DENINET-MNT
  • created: 2003-07-15T10:39:05Z
  • last-modified: 2017-10-30T21:46:03Z
  • route: 79.172.212.0/24
  • descr: Szerverplex Kft.
  • origin: AS61998
  • mnt-by: DENINET-MNT
  • created: 2014-04-09T15:42:15Z
  • last-modified: 2014-04-09T15:42:15Z

Links to attack logs

awsjap-redis-bruteforce-ip-list-2022-03-12