68.66.248.49 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 68.66.248.49 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 52/100

Host and Network Information

  • Mitre ATT&CK IDs: T1036.004 - Masquerade Task or Service, T1071.004 - DNS, T1102 - Web Service, T1105 - Ingress Tool Transfer, T1110.002 - Password Cracking, T1114.001 - Local Email Collection, T1185 - Man in the Browser, T1204.001 - Malicious Link, T1204.002 - Malicious File, T1204.003 - Malicious Image, T1447 - Delete Device Data, T1457 - Malicious Media Content, T1512 - Capture Camera, T1523 - Evade Analysis Environment, T1578.003 - Delete Cloud Instance, T1583.001 - Domains, T1588.001 - Malware, T1610 - Deploy Container

  • Tags: active related, added active, admin city, algorithm, aws, body length, business, compromised websites, country, cus olet, data, date, dev, dirtsearch, dns, dns resolutions, domain status, emotet, encrypt cnr11, entries, error, false, first, get http, huge domains, indicator role, ip address, kb body, key identifier, known infection source, learn more, malware, malware service, malware sites, mas, media sharing, number, organization, parking crew, postal code, post http, privacy admin, pulses, real estate, redacted for, related pulses, resolved ips, server, sha256, showing, spyware, stateprovince, status code, subject public, title added, ttl value, ua71173394, url http, url https, v3 serial, validity, x509v3 subject

  • JARM: 2ad2ad0002ad2ad00042d43d00041d598ac0c1012db967bb1ad0ff2491b3ae

  • View other sources: Spamhaus VirusTotal

Malware Detected on Host

Count: 12 917e549ea2770069f590e23acee7619b824694a600924144c8e0a18339622e51 96c0d2f042beae648cb721d2fd43beaf9b5762a641c3d5478e58db8d43b6ab97 8a6ac6aaa8fc029258663745116c13cca87510688a62134f4f580e5e221d6997 4b49ff02c3b61720ba557fd17b738ee559924ecc067c42d7d8b870e2aa732517 32947fc29580dbfc6f66a0eac6038e5374c446fb6e2b0f0c32d3d7aae7b55d8b 5ee51fa6eae9a9939cae60f7a3282888067054b1c8c286a5e669d16e9dd3a9d7 d8bab454c5692de5de9ae60b38c2142a7a9202525ecc88e18708a0de646dedcd f9c6fb11eb71bdda6761b6273501c637a30e2d2f29edb6cb8a1aa1319275833b 32d96ae58fa7178e8f5484d93d656c213872f4848027601703d228e265c8e626 fdee3e0b517f6662b1afef92eaccf0b65fddf4be42cffd736e61181aa1bfa707

Open Ports Detected

2079 2080 2083 2086 2087 2096 21 443 465 7822 80 993

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: