20.80.218.166 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 20.80.218.166 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
🟠 Elevated — 47/100
Geographic Location
Host and Network Information
- View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
- Country: United States
- Noticed: 1 time
- Protocols Attacked: SSH
- Countries Attacked: United States of America
- Open Ports: 443, 80
- Tor Node: No
Tags
- aaaa
- accept
- added active
- a domains
- ai device id
- america asn
- america flag
- appdata
- ascii text
- ashburn
- asn8075
- asp
- audio recording
- august
- av detections
- backdoor
- body
- botnet
- c++
- cameras
- certificate
- channel command
- ck id
- ck matrix
- ck techniques
- click
- colorado
- command
- contracts
- control att
- core
- creation date
- date
- decrypted ssl
- delete
- device local
- dns query
- dock
- domain
- domain add
- domains
- emails
- entries
- error
- evasion att
- execution
- expiration date
- fastly error
- file defense
- files
- files domain
- files ip
- files related
- found
- full service
- general
- general full
- hacking
- hash
- hashes
- high
- host
- hostname
- hostname add
- href
- http
- httponly
- hybrid
- icmp traffic
- informative
- internal
- ip address
- ipv4
- ipv4 add
- ireland
- learn
- local
- location united
- look
- malware
- medium
- memcommit
- microsoft
- microsoft oem
- mitre att
- monitored target
- moved
- mozilla
- mtb jun
- mtb may
- name servers
- name tactics
- name value
- nemtih
- netherlands
- next
- next associated
- passive dns
- patch
- path
- pattern match
- pdb path
- pe resource
- please
- port
- present apr
- present aug
- present jul
- present jun
- protocol h2
- pulses otx
- quasi
- read c
- refresh
- related pulses
- remote access
- remotewd
- resource hash
- restart
- reverse dns
- rgba
- role title
- running webserver
- runtime process
- samesitelax
- san jose
- script host
- sea p
- search
- security tls
- segoe ui
- show technique
- silencing campaign
- size
- software
- span
- spawns
- status
- strings
- suspicious
- svg scalable
- t1480 execution
- t1573 encrypted
- tactics
- tcp syn
- telnet
- test
- tools
- trojan
- trojandropper
- type indicator
- unicode
- united
- unknown ns
- url add
- url analysis
- url https
- urls
- verify
- virginia
- win32
- windows nt
- windows script
- write
- yara detections
MITRE ATT&CK TTPs
- T1001.003 - Protocol Impersonation
- T1027 - Obfuscated Files or Information
- T1053 - Scheduled Task/Job
- T1055 - Process Injection
- T1057 - Process Discovery
- T1068 - Exploitation for Privilege Escalation
- T1071 - Application Layer Protocol
- T1082 - System Information Discovery
- T1092 - Communication Through Removable Media
- T1105 - Ingress Tool Transfer
- T1119 - Automated Collection
- T1129 - Shared Modules
- T1133 - External Remote Services
- T1143 - Hidden Window
- T1210 - Exploitation of Remote Services
- T1433 - Access Call Log
- T1449 - Exploit SS7 to Redirect Phone Calls/SMS
- T1480 - Execution Guardrails
- T1568 - Dynamic Resolution
- T1573 - Encrypted Channel
- T1583.005 - Botnet
Passive DNS
- cuentaconuhc.com