91.216.107.78 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 91.216.107.78 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 20/100

Host and Network Information

  • JARM: 29d3fd00029d29d00042d43d0000000464fb8c6842ac133bede81390a48134

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: hphosts_psh

Malware Detected on Host

Count: 37 9550e54b5b90e375fc6d3d90d1d7a92b51c0b88049d5465ba42d0a0e1b2c56e2 4bcb70d288be65e1a417a52951c5775a27483e166e007a7714e7e21ace33c1cc 0d7e39e84d6595d6dbabbe63568159682d082ab66cfb05255bc78b9ba3008225 e4024149ddf4d86c5d9701fb15d50736640ba40303fc75a4b4f137449a6725b7 1e64e140b6f819725e6c52d24eadf0bb8d708927636d4ba62f64dab12762f88f bbb6710c23e6137a3ede9fc2986439d3f57b5f21b9206430602d6b493fd2776a e5331572b2ca735c59d2cee04bc4bb5852ce9398828ca1225a16b91ac43d75a0 afe35e2d79ed39b3e5008181f2dfc8329ecd641e8dadd886c6bfe5035255943b c4b625d41c86d1a48245f0edf2238cdc529d2b97d71559b5443dec765d1da5f9 88d3fc07b2795447ee319d42497f51641dd8ac0cf23ad7ccd514b6cfdf3cc908

Open Ports Detected

21 22 443 80

CVEs Detected

CVE-2016-10735 CVE-2018-14040 CVE-2018-14042 CVE-2018-20676 CVE-2018-20677 CVE-2019-8331

Map

Whois Information

  • inetnum: 91.216.107.0 - 91.216.107.255
  • netname: LWS-NET2
  • country: FR
  • org: ORG-LWSE1-RIPE
  • admin-c: DN930-RIPE
  • admin-c: LA7316-RIPE
  • tech-c: LA7316-RIPE
  • tech-c: DN930-RIPE
  • status: ASSIGNED PI
  • mnt-by: RIPE-NCC-END-MNT
  • mnt-by: LWS-MNT
  • mnt-by: RMI-MNT
  • mnt-routes: RMI-MNT
  • mnt-routes: LWS-MNT
  • mnt-domains: RMI-MNT
  • mnt-domains: LWS-MNT
  • mnt-irt: IRT-RMI
  • created: 2010-05-19T08:53:40Z
  • last-modified: 2022-03-09T13:16:57Z
  • organisation: ORG-LWSE1-RIPE
  • org-name: Groupe LWS SARL
  • country: FR
  • org-type: LIR
  • address: 2 rue jules ferry
  • address: 88190
  • address: Golbey
  • address: FRANCE
  • phone: +33177623003
  • admin-c: DN3291-RIPE
  • tech-c: DN3291-RIPE
  • abuse-c: AR31936-RIPE
  • mnt-ref: LWS-MNT
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: LWS-MNT
  • created: 2015-04-22T14:27:36Z
  • last-modified: 2020-12-22T11:38:57Z
  • role: LWS
  • address: 2 rue jules ferry 88190 Golbey
  • nic-hdl: LA7316-RIPE
  • mnt-by: LWS-MNT
  • mnt-by: fr-lws-1-mnt
  • created: 2018-07-16T12:36:14Z
  • last-modified: 2018-07-16T12:56:04Z
  • tech-c: EV3761-RIPE
  • admin-c: EV3761-RIPE
  • tech-c: DN930-RIPE
  • admin-c: DN930-RIPE
  • person: Depredurand Nicolas
  • address: Ligne Web Services
  • address: 4 rue galvani
  • address: 75017 PARIS
  • address: France
  • phone: +33826102413
  • nic-hdl: DN930-RIPE
  • mnt-by: LWS-MNT
  • created: 2006-02-28T08:58:04Z
  • last-modified: 2017-11-07T13:16:10Z
  • route: 91.216.107.0/24
  • origin: AS210403
  • mnt-by: LWS-MNT
  • mnt-by: fr-lws-1-mnt
  • mnt-by: LWS-MNT
  • mnt-by: fr-lws-1-mnt
  • created: 2022-06-22T15:00:20Z
  • last-modified: 2022-06-22T15:00:20Z
Share on: