80.249.146.32 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Possibly Malicious Host 🟢 20/100

Host and Network Information

  • Tags: C&C
  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS49505 ooo network of data-centers selectel
  • Noticed: 12 times
  • Protcols Attacked: ssh
  • Passive DNS Results: ermakovskaya.famed.online haroldreadlife.info recipeskitchen.info

Malware Detected on Host

Count: 3 d5b3bfbe971e770fa700050338914317d80ae4c85be2718e07cb39fa8e8a338f 029ae517a07624221886a5f2e15bbbecff3d2afed842e4b52eafaec1409f87d7 029ae517a07624221886a5f2e15bbbecff3d2afed842e4b52eafaec1409f87d7

Open Ports Detected

3000 443 80

Map

Whois Information

  • inetnum: 80.249.146.0 - 80.249.146.255
  • netname: SELECTEL-NET
  • descr: Selectel Network
  • country: RU
  • geofeed: https://1581710f-1ced-4a06-8390-7cc61076f103.selcdn.net/geofeed.csv
  • admin-c: SA32710-RIPE
  • tech-c: SA32710-RIPE
  • status: ASSIGNED PA
  • mnt-by: MNT-SELECTEL
  • created: 2019-08-16T16:02:17Z
  • last-modified: 2022-10-25T14:50:58Z
  • role: SELECTEL-NOC
  • address: Russia, Saint-Petersburg, Cvetochnaya st. 21
  • admin-c: CMH-RIPE
  • admin-c: KS9134-RIPE
  • admin-c: TL5407-RIPE
  • admin-c: RVA179-RIPE
  • admin-c: EN5675-RIPE
  • admin-c: NS8369-RIPE
  • admin-c: AD16782-RIPE
  • tech-c: CMH-RIPE
  • tech-c: KS9134-RIPE
  • tech-c: TL5407-RIPE
  • tech-c: RVA179-RIPE
  • tech-c: EN5675-RIPE
  • tech-c: NS8369-RIPE
  • tech-c: AD16782-RIPE
  • nic-hdl: SA32710-RIPE
  • mnt-by: mnt-selectel
  • created: 2015-01-19T15:40:16Z
  • last-modified: 2022-02-01T12:36:04Z
  • route: 80.249.144.0/22
  • descr: SELECTEL-NET
  • origin: AS49505
  • mnt-by: MNT-SELECTEL
  • created: 2019-08-16T16:05:18Z
  • last-modified: 2019-08-16T16:05:18Z

Links to attack logs

vultrwarsaw-ssh-bruteforce-ip-list-2023-03-28