20.80.218.166 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 20.80.218.166 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 47/100
Host and Network Information
-
Mitre ATT&CK IDs: T1001.003 - Protocol Impersonation, T1027 - Obfuscated Files or Information, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1057 - Process Discovery, T1068 - Exploitation for Privilege Escalation, T1071 - Application Layer Protocol, T1082 - System Information Discovery, T1092 - Communication Through Removable Media, T1105 - Ingress Tool Transfer, T1119 - Automated Collection, T1129 - Shared Modules, T1133 - External Remote Services, T1143 - Hidden Window, T1210 - Exploitation of Remote Services, T1433 - Access Call Log, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1480 - Execution Guardrails, T1568 - Dynamic Resolution, T1573 - Encrypted Channel, T1583.005 - Botnet
-
Tags: aaaa, accept, added active, a domains, ai device id, america asn, america flag, appdata, ascii text, ashburn, asn8075, asp, audio recording, august, av detections, backdoor, body, botnet, c++, cameras, certificate, channel command, ck id, ck matrix, ck techniques, click, colorado, command, contracts, control att, core, creation date, date, decrypted ssl, delete, device local, dns query, dock, domain, domain add, domains, emails, entries, error, evasion att, execution, expiration date, fastly error, file defense, files, files domain, files ip, files related, found, full service, general, general full, hacking, hash, hashes, high, host, hostname, hostname add, href, http, httponly, hybrid, icmp traffic, informative, internal, ip address, ipv4, ipv4 add, ireland, learn, local, location united, look, malware, medium, memcommit, microsoft, microsoft oem, mitre att, monitored target, moved, mozilla, mtb jun, mtb may, name servers, name tactics, name value, nemtih, netherlands, next, next associated, passive dns, patch, path, pattern match, pdb path, pe resource, please, port, present apr, present aug, present jul, present jun, protocol h2, pulses otx, quasi, read c, refresh, related pulses, remote access, remotewd, resource hash, restart, reverse dns, rgba, role title, running webserver, runtime process, samesitelax, san jose, script host, sea p, search, security tls, segoe ui, show technique, silencing campaign, size, software, span, spawns, status, strings, suspicious, svg scalable, t1480 execution, t1573 encrypted, tactics, tcp syn, telnet, test, tools, trojan, trojandropper, type indicator, unicode, united, unknown ns, url add, url analysis, url https, urls, verify, virginia, win32, windows nt, windows script, write, yara detections
-
View other sources: Spamhaus VirusTotal
- Country: United States
- Network:
- Noticed: 1 times
- Protocols Attacked: SSH
- Countries Attacked: United States of America
- Passive DNS Results: cuentaconuhc.com www.uhcstayingactive.com uhccands.uhc.com www.uhcexchange.com uhcexchange.com newsroom.uhc.com uhg6-prod.adobecqms.net uhg6-prod-eastus2-appgateway1-publicip.eastus2.cloudapp.azure.com stage-uhcexchange.uhc.com offline-blog.medicaremadeclear.com www.uhcretiree.com blog.medicaremadeclear.com www.mychoicenotchance.com www.source4women.com digital.uhc.com www.medicaremadeclear.com engage.uhc.com www.healthyatcola.com www.stage-medicaremadeclear.uhc.com www.offline-medicaremadeclear.uhc.com www.engage.uhc.com www.uhcgenerations.com blog.stage-medicaremadeclear.uhc.com www.designwithcare.com beasmartpatient.com accountablecareanswers.com www.uhcpremium.com onenetppo.com unitedhealthpremium.com www.uhctogether.com www.unitedhealthcare.com uhc.com healthinnumbers.com www.accountablecareanswers.com uhctogether.com offline-medicaremadeclear.uhc.com medicaremadeclear.com www.everypregnancy.com source4women.com unitedhealthcare.com uhcretiree.com designwithcare.com www.onenetppo.com stage-medicaremadeclear.uhc.com mychoicenotchance.com www.unitedhealthpremium.com everypregnancy.com www.beasmartpatient.com uhcpremium.com healthyatcola.com uhcgenerations.com uhc-ams-offline.uhc.com ei-ams-origin.uhc.com retiree-ams-origin.uhc.com
Open Ports Detected
Map
Whois Information
- NetRange: 20.33.0.0 - 20.128.255.255
- CIDR: 20.128.0.0/16, 20.40.0.0/13, 20.34.0.0/15, 20.64.0.0/10, 20.36.0.0/14, 20.48.0.0/12, 20.33.0.0/16
- NetName: MSFT
- NetHandle: NET-20-33-0-0-1
- Parent: NET20 (NET-20-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Microsoft Corporation (MSFT)
- RegDate: 2017-10-18
- Updated: 2021-12-14
- Ref: https://rdap.arin.net/registry/ip/20.33.0.0
- OrgName: Microsoft Corporation
- OrgId: MSFT
- Address: One Microsoft Way
- City: Redmond
- StateProv: WA
- PostalCode: 98052
- Country: US
- RegDate: 1998-07-10
- Updated: 2025-06-10
- Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to:
- Comment: * https://cert.microsoft.com.
- Comment:
- Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact:
- Comment: * abuse@microsoft.com.
- Comment:
- Comment: To report security vulnerabilities in Microsoft products and services, please contact:
- Comment: * secure@microsoft.com.
- Comment:
- Comment: For legal and law enforcement-related requests, please contact:
- Comment: * msndcc@microsoft.com
- Comment:
- Comment: For routing, peering or DNS issues, please
- Comment: contact:
- Comment: * IOC@microsoft.com
- Ref: https://rdap.arin.net/registry/entity/MSFT
- OrgRoutingHandle: CHATU3-ARIN
- OrgRoutingName: Chaturmohta, Somesh
- OrgRoutingPhone: +1-425-882-8080
- OrgRoutingEmail: someshch@microsoft.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN
- OrgTechHandle: BEDAR6-ARIN
- OrgTechName: Bedard, Dawn
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: dabedard@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN
- OrgTechHandle: IPHOS5-ARIN
- OrgTechName: IPHostmaster, IPHostmaster
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: iphostmaster@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN
- OrgTechHandle: SINGH683-ARIN
- OrgTechName: Singh, Prachi
- OrgTechPhone: +1-425-707-5601
- OrgTechEmail: pracsin@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN
- OrgAbuseHandle: MAC74-ARIN
- OrgAbuseName: Microsoft Abuse Contact
- OrgAbusePhone: +1-425-882-8080
- OrgAbuseEmail: abuse@microsoft.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN
- OrgTechHandle: MRPD-ARIN
- OrgTechName: Microsoft Routing, Peering, and DNS
- OrgTechPhone: +1-425-882-8080
- OrgTechEmail: IOC@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN