166.62.28.106 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 166.62.28.106 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Tags: cyber security, ioc, malicious, Nextray, phishing

  • JARM: 2ad2ad16d2ad2ad0002ad2ad2ad2ad783c15df386a8f7b030295f1ff4c2373

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: cleanmx_phishing, cleanmx_viruses, hphosts_emd, hphosts_fsa

Malware Detected on Host

Count: 5 3b14e3fb47e8fbbba07a01b329e9bd128dbba59db58a02e353368adad43ade92 8832de54848c35df3e32e0b7c4ed84d791e62699015b5298d78759ecd543a4e2 4f2225ef374afb7657ada6a4f14aacede585cbd37cd9d740f3771b35fb75db3a 0af0ac897b098cbe8df904334efa735b40627aa4c6b7ae13f8b81f1f33e573e4 e344cd7c7dde315cbc583cb0b719bba4bb56a82fc94176d2861b101ca76eb0fd

Open Ports Detected

110 2082 21 22 25 3306 443 465 587 80 993 995

CVEs Detected

CVE-2007-2768 CVE-2007-3205 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2013-2220 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2017-8923 CVE-2018-15473 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-15778 CVE-2021-36368 CVE-2022-31628 CVE-2022-31629 CVE-2022-37454 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: