68.66.226.85 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 68.66.226.85 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 44/100

Host and Network Information

  • Tags: aaaa, algorithm, all scoreblue, are you hiring, as35819, as44273 host, asnone united, auto-generated security, cancer, chrome, class, cname, component, cyber attack, delphi, delphi generic, dns resolutions, domains, dynadot inc, dynamicloader, error, files, file type, format, gamers, get http, gmt content, hackers, hashes, historical ssl, http requests, info header, inno5311, inno setup, intel, invalid variant, ip traffic, ipv4, javascript, kb file, language, legalcopyright, linker, malware, malware fighter, medium, mesh digital, module, moved, msie, ms windows, name md5, name servers, network, nxdomain, overlay, passive dns, pe32, pe32 installer, pe resource, read, red team, referrer, serial number, sha256 code, showing, signing ca, spotify artist, stack, stamping, story, symantec time, temp, the bazar, thumbprint, time stamping, uninstall iobit, united states, unknown, valid, valid usage, variant, whitelisted, widgitoolbar, win32, win32 dll, win32 exe, windows, windows nt, write

  • JARM: 2ad2ad0002ad2ad00042d43d00041d598ac0c1012db967bb1ad0ff2491b3ae

  • View other sources: Spamhaus VirusTotal

Malware Detected on Host

Count: 14 c3b2f4b2b6e23610923038798c9842f32b5d20a8dc9e2aa7283c918873f1c5d5 abecd4cff9aa74cb04c97f082fc711fa50b68ee313b2ff8d3def382593079cd9 f5f4ba17bf5f463d96211c27ffcf66fca80b5841a7a267833f38790ab292fc77 c8a0c5cb68c3adadef20224d76ffa124d973423cbcbc24aaf0d3269274817c7b 9c74e2b701d59e421e07e63e175affbe81c7dbce09244f3580064f389adc3133 f64364833194b2df03b7ddf623cd31d4210bf2ad80b3a15c87564aa5ac684164 0fe96220504b4880101f8cb8ad032b1ad73cdc73092f047abb90a73efc852277 f509680d0208208a9d59def8faf160da57c0eeff09239ea4f9db7cbd29cb088f f8717173adc18cb4adea90ae5abeea523486ba4a06122b71db15c2a11a22353e 0af451e6a027a2fe9d60ac8adf30b759a8a5e219a4e1904aad9f044220cc2cb8

Open Ports Detected

2077 2079 2080 2525 443 7822 80 995

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465 CVE-2025-30232 CVE-2025-32728

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: