45.113.122.166 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 45.113.122.166 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Known Malicious Host 🔴 85/100

Host and Network Information

  • Mitre ATT&CK IDs: T1021.001 - Remote Desktop Protocol, T1110 - Brute Force, T1184 - SSH Hijacking, T1192 - Spearphishing Link, T1194 - Spearphishing via Service, T1442 - Fake Developer Accounts, T1454 - Malicious SMS Message, T1566 - Phishing, T1583.001 - Domains, T1583.006 - Web Services, T1585.001 - Social Media Accounts, T1586 - Compromise Accounts, T1591.002 - Business Relationships

  • Tags: anydesk, as15169 as16509, as19871 as22612, as9002, business email compromise, c2, caas, cyber security, fraud, hosting, identifying, ioc, malicious, Nextray, parked domains, phishing, scams, ssh hijacking, typosquatting

  • JARM: 29d29d15d29d29d00042d42d0000009435214b849738c4ebab4534b5d158dd

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: cleanmx_phishing, hphosts_emd, hphosts_fsa, hphosts_psh

Malware Detected on Host

Count: 34 8ca54a884f41212c7a9bf86f07ec1366cf868595ec928f2ab98f6a098e2f3d98 e323b600e79ee0a5c009b98d373a507b269dd5318e2d151f6c2916500706cd9e 59b43798bb352b5ebd6be400caeaafdfe3dbeb48d337d56da841d8cd00db1fbc 75141afc5bcc8a1e10c72a502fc8f8e77d21b6cd5a744bc4398073223b230586 3895d1eac4f86d0c82dfa1d92047f2549a1db8dae7aa06240f6e52720de7c5a6 304bd2fb520c86d8892f98e9a1a90681628bfef7ced52436968f9b2bc3012c91 50052f447f4133485d41a4885f3a5af94fc68446f6e306165bab0abf806798ff 56977a42264f537b85e66c0b400e947ff7efd57cb4d1713731bcf0c976a0ab01 6de4120bce9c7cbaca9a3e2ffe984e30a46787cb5e670248acad9a29a9215edc 2ebc04d6c76e0789de9bedbf5f8ab415c60170a1a7442bc226b81224210f202d

Open Ports Detected

110 2082 2083 2086 2087 2095 2096 21 22 2222 26 3306 443 53 80 993 995

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465 CVE-2025-32728

Map

Whois Information

  • inetnum: 45.113.120.0 - 45.113.123.255
  • netname: HGINDIA-AP
  • descr: Hostgator.com LLC
  • country: IN
  • org: ORG-HL14-AP
  • admin-c: HIND1-AP
  • tech-c: HIND1-AP
  • abuse-c: AH851-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: APNIC-HM
  • mnt-lower: MAINT-HGINDIA-AP
  • mnt-routes: MAINT-HGINDIA-AP
  • mnt-irt: IRT-HGINDIA-AP
  • last-modified: 2020-05-27T09:45:30Z
  • irt: IRT-HGINDIA-AP
  • address: 1st Floor, Near Mahatma Nagar Cricket Ground, Mahatma Nagar, Nashik, Maharashtra, India
  • e-mail: net-eng-team@newfold.com
  • abuse-mailbox: abuse@publicdomainregistry.com
  • admin-c: HIND1-AP
  • tech-c: HIND1-AP
  • mnt-by: MAINT-HGINDIA-AP
  • last-modified: 2025-05-11T07:51:30Z
  • organisation: ORG-HL14-AP
  • org-name: Hostgator.com LLC
  • org-type: LIR
  • country: US
  • address: Endurance International Group
  • address: 10 Corporate Drive, Burlington, MA 01803 US
  • phone: +1-781-852-3200
  • e-mail: eig-net-team@endurance.com
  • mnt-ref: APNIC-HM
  • mnt-by: APNIC-HM
  • last-modified: 2023-09-05T02:15:46Z
  • role: ABUSE HGINDIAAP
  • country: ZZ
  • address: 1st Floor, Near Mahatma Nagar Cricket Ground, Mahatma Nagar, Nashik, Maharashtra, India
  • phone: +000000000
  • e-mail: net-eng-team@newfold.com
  • admin-c: HIND1-AP
  • tech-c: HIND1-AP
  • nic-hdl: AH851-AP
  • abuse-mailbox: abuse@publicdomainregistry.com
  • mnt-by: APNIC-ABUSE
  • last-modified: 2025-05-11T07:51:50Z
  • role: Hostgator India - Network Division
  • address: Near Kings Park Layout, Maryhill, Mangalore 575 015, Karnataka, India
  • country: IN
  • phone: +14152300648
  • e-mail: abuse@hostgator.in
  • admin-c: HIND1-AP
  • tech-c: HIND1-AP
  • nic-hdl: HIND1-AP
  • mnt-by: MAINT-HGINDIA-AP
  • last-modified: 2017-03-09T09:57:33Z

Links to attack logs

****** ****** ******

Share on: