85.93.41.25 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Possibly Malicious Host 🟢 10/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS12389 pjsc rostelecom
  • Noticed: 1 times
  • Protcols Attacked: SSH

Malware Detected on Host

Count: 2291 6b6ae9cd1c7155655e718d14fba168ef4129f38de01d17116476fdfe53d8dde8 b65b7bb28d76aa10b3488d5fa1a33ae849b738505725f4796dea642423c44e7c 4b19f7d82f1574d6e0fceb239a9f71868abdb51f6372e4008babf3d3d8c0b74b 060f89f9ccfb00a65f9f2aa2aed7bee7ea20688b9d510708d14ac17d62ab8240 3961b6ca4fca0a90233cfb7f73b78f6f72d39b6cb75a255f23a3041675b5be50 3a1e79caea5b3af0ed3a9db413d8dd6cc61d816e5f83f8d4a8c99cc4d8cbbc8e 5b2701768cd508f65bb7f3a99d895c883c37291333ff33ab4e98d44a25a8f67d 637d28336968a3685fdcb4d0e90f9548e5d23b1cf4182d58eab588d4e60249d5 56b0cc23c1b4bf119a9066914632a6cf4b2aea9eb9caebbfb5e2b38c4504ae12 3c63bb57e90453101891dd8b124c8288f32256f47a0144251fd49eb157d2afda

Open Ports Detected

123 22 4000 5432 6379 80

Map

Whois Information

  • inetnum: 85.93.41.0 - 85.93.41.255
  • netname: KIROV-xDSL-LEASED
  • descr: Kirov xDSL leased line customers
  • country: ru
  • admin-c: MAB88-RIPE
  • tech-c: MAB88-RIPE
  • status: ASSIGNED PA
  • mnt-by: CAIT-MNT
  • created: 2006-05-19T05:40:22Z
  • last-modified: 2008-09-25T13:18:42Z
  • person: Michail Bilkevich
  • address: 20 Moskovskaya st., Kirov, Russia, 610000
  • address: JSC “RosTelecom”, Kirov branch
  • phone: +7-8332-702981
  • nic-hdl: MAB88-RIPE
  • created: 2006-05-22T08:55:17Z
  • last-modified: 2020-08-19T06:47:18Z
  • mnt-by: CAIT-MNT
  • route: 85.93.32.0/20
  • descr: JSC RosTelecom, Kirov branch
  • origin: AS25436
  • mnt-by: CAIT-MNT
  • created: 2008-05-27T09:00:58Z
  • last-modified: 2012-10-09T09:49:45Z

Links to attack logs

roxy-ip-list-2023-05-03 roxy-ip-list-2023-05-05