85.30.248.210 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Tags: Cyclops, Gamardeon, HermeticWiper, IsaacWiper, Nextray, PartyTicket, WhisperGate, cyber security, ioc, malicious, phishing, tsec
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: nixspam, php_commenters_30d, php_commenters_7d, socks_proxy_1d, socks_proxy_30d, socks_proxy_7d, stopforumspam, stopforumspam_180d, stopforumspam_365d, stopforumspam_90d

  • Country: Russian Federation
  • Network: AS42610 pjsc rostelecom
  • Noticed: 19 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 3 9a9be2b5e5a52484db8dec3e3235624788961f9aa73e8448e19de408469dace5 5ee96cce83902ae9cb52fafac4479412f4d12bfc9b699cb81763f140e7b979a8 9e44fe6f54a1f2dfe3907b06986ced80473e20d52f0ba6c2a14d1fda608b5d55

Map

Whois Information

  • inetnum: 85.30.240.0 - 85.30.249.255
  • netname: NCN-BBCUST
  • descr: NCNET Broadband customers
  • country: RU
  • admin-c: NCN7-RIPE
  • tech-c: NCN7-RIPE
  • status: ASSIGNED PA
  • mnt-by: NCNET-MNT
  • created: 2014-02-19T06:56:40Z
  • last-modified: 2014-02-19T06:56:40Z
  • role: NCNET NCC Operations
  • address: National Cable Networks
  • address: Nagatinskaya str., 1, bldn. 26
  • address: 117105 Moscow, Russia
  • org: ORG-NCN1-RIPE
  • admin-c: RVP-RIPE
  • tech-c: RVP-RIPE
  • phone: +7 495 6859542
  • fax-no: +7 495 6859530
  • mnt-by: NCNET-MNT
  • nic-hdl: NCN7-RIPE
  • created: 2007-03-26T07:46:58Z
  • last-modified: 2015-10-12T11:53:05Z
  • abuse-mailbox: [email protected]
  • route: 85.30.240.0/20
  • descr: delegated block for Corvette Telecom
  • origin: AS35078
  • mnt-by: CVT-MNT
  • created: 2006-07-31T13:34:24Z
  • last-modified: 2006-07-31T13:34:24Z

Links to attack logs

roxy-ip-list-2023-05-03 roxy-ip-list-2023-05-05