18.208.85.101 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 18.208.85.101 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 20/100
Host and Network Information
- View other sources: Spamhaus VirusTotal
- Country: United States
- Network: AS14618 amazon.com inc.
- Noticed: 1 times
- Protocols Attacked: SSH
Malware Detected on Host
Count: 110 494c8deec3bcf68a4892fccf3c81d37a7a8f68ee4f44c083b263a71386d4b1e7 2ca0595713c8c500950dcf66e1005a50cceb848ee9bf61da6496ebfe6e38ab67 3ca87383a75ceca1014ba4a7fd8378d01f03334433f46d44d20fa88cb1e230f2 9457dcd4b2566d9ed1791c4e3e831d29b56856a7c6a5a4e39ecfb57e4eccd806 9c9b0ff086986628a534f733628183fcd0d7dde37688720e3e47339c5c74f630 ae28ccfbf0a530effd5f06882539cb6b6e7878380ab09ea8ad60d1f5fdf3c298 119f316d6484f99969e0ff603431958ea93d84b3a7608a4c6d1110023a55b76e 29448f4e050cdc6905111cbb78ee45551465a25b38be18be9e00bfa7d801fb8c a1c29d9b6e1611415f5032afe405a16b42eb77c6be94a901b5b7a38e22c135f1 f3befb3718f6c18d7952a7bb0c128289f3a56d0d8eab26a2750e459db598210b
Open Ports Detected
CVEs Detected
CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2024-6387
Map
Whois Information
- NetRange: 18.32.0.0 - 18.255.255.255
- CIDR: 18.64.0.0/10, 18.32.0.0/11, 18.128.0.0/9
- NetName: AT-88-Z
- NetHandle: NET-18-32-0-0-1
- Parent: NET18 (NET-18-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Amazon Technologies Inc. (AT-88-Z)
- RegDate: 2019-10-07
- Updated: 2021-02-10
- Ref: https://rdap.arin.net/registry/ip/18.32.0.0
- OrgName: Amazon Technologies Inc.
- OrgId: AT-88-Z
- Address: 410 Terry Ave N.
- City: Seattle
- StateProv: WA
- PostalCode: 98109
- Country: US
- RegDate: 2011-12-08
- Updated: 2024-01-24
- Comment: All abuse reports MUST include:
- Comment: * src IP
- Comment: * dest IP (your IP)
- Comment: * dest port
- Comment: * Accurate date/timestamp and timezone of activity
- Comment: * Intensity/frequency (short log extracts)
- Comment: * Your contact details (phone and email) Without these we will be unable to identify the correct owner of the IP address at that point in time.
- Ref: https://rdap.arin.net/registry/entity/AT-88-Z
- OrgNOCHandle: AANO1-ARIN
- OrgNOCName: Amazon AWS Network Operations
- OrgNOCPhone: +1-206-555-0000
- OrgNOCEmail: amzn-noc-contact@amazon.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/AANO1-ARIN
- OrgAbuseHandle: AEA8-ARIN
- OrgAbuseName: Amazon EC2 Abuse
- OrgAbusePhone: +1-206-555-0000
- OrgAbuseEmail: trustandsafety@support.aws.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
- OrgRoutingHandle: ARMP-ARIN
- OrgRoutingName: AWS RPKI Management POC
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-rpki-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ARMP-ARIN
- OrgRoutingHandle: IPROU3-ARIN
- OrgRoutingName: IP Routing
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/IPROU3-ARIN
- OrgTechHandle: ANO24-ARIN
- OrgTechName: Amazon EC2 Network Operations
- OrgTechPhone: +1-206-555-0000
- OrgTechEmail: amzn-noc-contact@amazon.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN