199.79.63.203 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 199.79.63.203 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Known Malicious Host 🔴 72/100

Host and Network Information

  • Mitre ATT&CK IDs: T1021.001 - Remote Desktop Protocol, T1110 - Brute Force, T1184 - SSH Hijacking, T1192 - Spearphishing Link, T1194 - Spearphishing via Service, T1442 - Fake Developer Accounts, T1454 - Malicious SMS Message, T1566 - Phishing, T1583.001 - Domains, T1583.006 - Web Services, T1585.001 - Social Media Accounts, T1586 - Compromise Accounts, T1591.002 - Business Relationships

  • Tags: anydesk, as15169 as16509, as19871 as22612, as9002, business email compromise, c2, caas, fraud, hosting, identifying, parked domains, scams, ssh hijacking, typosquatting

  • JARM: 29d29d15d29d29d00042d42d0000009435214b849738c4ebab4534b5d158dd

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: blocklist_net_ua, hphosts_emd, hphosts_psh

Malware Detected on Host

Count: 26 0cb72658adcf92c068b12cc2bcc4a602707f802c353bb1f2f29ded122d673abc ae17d4e7bf4eadc4fc27490bc70dfc28ebe148a0b0684915cd41fa0e6edab494 a202231754cf06cce4e27f60a6e64988c3aca08af4fb8e0b7a8b10bf06613dbe 06132dd35f879ce9935e0c8a47a1fcb7169b05a86d7f9c5291a614e0a0848467 2150a328e3864f8593e8c528d87f8740b78b44159bdd49d1f84877dcba706d1f b68093d0e5c20ed7bde466053b7b75496b7ec1e40ea917c5f4bcff6b6dd4f0a2 2706f32f91b678e5597b793c9087ccc06825f9a99fb5babc3f413a04f6d01ef3 5aa6983bc50985285d634d6622ab67dc3a3e18a55688308b859d93a116938553 9e5183984ccdba29856877f2fc2721b59769561e260f88923f36210700676e58 9df69119644fe42b643d8e6b8e3aa2abe9935bba4a5302908f2abcaaaa038e6c

Open Ports Detected

110 143 2077 2082 2083 2086 2087 21 22 2222 26 3306 443 465 53 587 80 993 995

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-11358 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-11022 CVE-2020-11023 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: