68.66.248.49 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 68.66.248.49 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 52/100
Host and Network Information
-
Mitre ATT&CK IDs: T1036.004 - Masquerade Task or Service, T1071.004 - DNS, T1102 - Web Service, T1105 - Ingress Tool Transfer, T1110.002 - Password Cracking, T1114.001 - Local Email Collection, T1185 - Man in the Browser, T1204.001 - Malicious Link, T1204.002 - Malicious File, T1204.003 - Malicious Image, T1447 - Delete Device Data, T1457 - Malicious Media Content, T1512 - Capture Camera, T1523 - Evade Analysis Environment, T1578.003 - Delete Cloud Instance, T1583.001 - Domains, T1588.001 - Malware, T1610 - Deploy Container
-
Tags: active related, added active, admin city, algorithm, aws, body length, business, compromised websites, country, cus olet, data, date, dev, dirtsearch, dns, dns resolutions, domain status, emotet, encrypt cnr11, entries, error, false, first, get http, huge domains, indicator role, ip address, kb body, key identifier, known infection source, learn more, malware, malware service, malware sites, mas, media sharing, number, organization, parking crew, postal code, post http, privacy admin, pulses, real estate, redacted for, related pulses, resolved ips, server, sha256, showing, spyware, stateprovince, status code, subject public, title added, ttl value, ua71173394, url http, url https, v3 serial, validity, x509v3 subject
-
JARM: 2ad2ad0002ad2ad00042d43d00041d598ac0c1012db967bb1ad0ff2491b3ae
-
View other sources: Spamhaus VirusTotal
- Country: United States
- Network:
- Noticed: 1 times
- Protocols Attacked: SSH
- Passive DNS Results: infinivisionai.com giffgaff-sim-only-deals.online www.safeboxworld.com safeboxworld.com sea-master.gr www.rzeenstore.com rzeenstore.com www.ccmbilgisayar.com.behlevan.com riccardobiolo.com www.riccardobiolo.com mail.takbord-domain.shop uniquesoundandlight.com www.arabicolympiad.org www.csc-luganofr.istitutoelveticodigaranzia.ch csc-luganofr.istitutoelveticodigaranzia.ch www.aleclothing.a2hosted.com alecyclingkit.co.uk aleclothing.a2hosted.com www.alecyclingkit.co.uk www.livioagenziagenerale.ch.istitutoelveticodigaranzia.ch livioagenziagenerale.ch.istitutoelveticodigaranzia.ch livioagenziagenerale.ch www.thaiessence-atwindsor.co.uk thaiessence-atwindsor.co.uk inecoenergy.com www.inecoenergy.com www.malsoon.uxpan.net malsoon.uxpan.net hamsat.aliacademy.online www.hamsat.aliacademy.online www.verifica.istitutoelveticodigaranzia.ch verifica.istitutoelveticodigaranzia.ch www.funlandistanbul.com.behlevan.com funlandistanbul.com www.sisco.uxpan.net sisco.uxpan.net www.naptimestudio.co.uk.plattypus.co.uk www.purgatories.co.uk.plattypus.co.uk naptimestudio.co.uk naptimestudio.co.uk.plattypus.co.uk purgatories.co.uk.plattypus.co.uk purgatories.co.uk www.ronanristord.hettykate.com over11-domain.shop reflexia.eu winiston-domain.shop yasbet-domain.shop takbord-domain.shop winamit-domain.shop hiwino-domain.shop www.experiance.skybluecreatives.co.uk experiance.skybluecreatives.co.uk universaldoortech.co.uk gemi.fitoidea.gr www.gemi.fitoidea.gr infinitytranslation.co www.infinitytranslation.co mme.enxaquecas.pt www.mme.enxaquecas.pt invest6.co.uk www.invest6.co.uk rupertevanshydrologist.com cruiseonlinebooking.com.cruise.a2hosted.com cruiseonlinebooking.com www.cruiseonlinebooking.com.cruise.a2hosted.com www.datatechimmobiliare.com www.tsalopoulos.com.gr.sgahosting01.a2hosted.com tsalopoulos.com.gr.sgahosting01.a2hosted.com docpro.apexappsng.com www.docpro.apexappsng.com html.istitutoelveticodigaranzia.ch www.html.istitutoelveticodigaranzia.ch new.aliacademy.online www.new.aliacademy.online www.rapidwebservices.co.uk.sg6.co.uk rapidwebservices.co.uk.sg6.co.uk profiles.mapworldlive.com www.profiles.mapworldlive.com pebblemirror.com emprendimientooportunidadescm.es www.safeboxgroup.it safeboxgroup.it www.dalkeytaxi.ie gwdkenya.gulfworldwide.net www.gwdkenya.gulfworldwide.net www.medaja.com www.affittopro.com moi.digicode.com.cy datatechimmobiliare.com portal2024.hakomimallorca.com www.portal2024.hakomimallorca.com www.expertsinhospitality.me bricksstarter.developmentandtesting.co.uk www.happeninibiza.com teverun.es www.teverun.es standrewshw.developmentandtesting.co.uk oraib.co.uk www.phpmyadmin.istitutoelveticodigaranzia.ch phpmyadmin.istitutoelveticodigaranzia.ch imersaodesbloquear.pt evermindtech.com www.thaitastic-llandudno.co.uk thaitastic-llandudno.co.uk naturalifeoldsite.com megadealsoman.com.grandsouq.ae www.megadealsoman.com.grandsouq.ae minerva.gal www.rzeen.ae servicedeskexperts.com panduvia.sk www.loftplan.nomad-developer.co.uk www.daleelgroup.aliacademy.online daleelgroup.aliacademy.online www.elecoride.com elecoride.com saytrust.co.uk skybluecreatives.co.uk clinicaimmobiliare.com bonus.casewonderwall.com offerta.casewonderwall.com www.etc-bh.me etc-bh.me terseus.com pashmina.bio www.video.keyframeworks.com video.keyframeworks.com techstud.net home.lavridsen.dk www.home.lavridsen.dk nuom.ae micromoves.gr www.portal2025.hakomimallorca.com portal2025.hakomimallorca.com www.live.keyframe.me live.keyframe.me hunthavoc.developmentandtesting.co.uk grippertireinflator.developmentandtesting.co.uk www.jardimgomes-com-pt.ricarela.info jardimgomes-com-pt.ricarela.info ethicability.org bartonbrooksmysteries.com happeninibiza.com armenoidconstruction.com.skybluephotography.co.uk www.armenoidconstruction.com.skybluephotography.co.uk jmadeira.pt finanzas.amigovagabundoteatro.com www.finanzas.amigovagabundoteatro.com grandsouq.ae andermanngroup.com www.andermanngroup.com www.zwz.co.in www.pathtopresence.co.uk.plattypus.co.uk pathtopresence.co.uk pathtopresence.co.uk.plattypus.co.uk methodikal.gr www.dexcelencia.com.legendatours.net dexcelencia.com.legendatours.net collegeoverdeliefde.nl gynaikologoskalamaria.gr www.will.elliottbear.co.uk will.elliottbear.co.uk hob.nomad-developer.co.uk qa.techstud.net voteclimate.developmentandtesting.co.uk ssandboxx.com www.mybettercolors.com willrhodesgardenmaintenance.co.uk lookatit.pt powertecgarden.com strokeme.ae bricks.developmentandtesting.co.uk tpc.developmentandtesting.co.uk www.bravaciao.com expertsinhospitality.me billyszepphreaksclub.com criticalthinkingenvironment.developmentandtesting.co.uk futureperfect.developmentandtesting.co.uk triangle.developmentandtesting.co.uk dekkoid.incloudskills.com www.dekkoid.incloudskills.com kswealthifa.co.uk www.kswealthifa.co.uk www.t.uxpan.net t.uxpan.net wiabiliza.pt www.fotomomentje.eu fotomomentje.eu succesvollebouw.nl www.succesvollebouw.nl www.vorpra.com vorpra.com enxaquecas.pt www.gcafe.enxaquecas.pt www.conlis.enxaquecas.pt www.sarakatsanosatee.gr.plantech5.a2hosted.com www.thewellsuites.gr.plantech5.a2hosted.com sofmed.dailybiz.gr www.sofmed.dailybiz.gr app.centrallymanaged.ai medi1.app www.seomaggie.com.ricarela.info seomaggie.com.ricarela.info www.portfolio.showmyweb.co.uk www.mooi.elliottbear.co.uk mooi.elliottbear.co.uk blmont.sk seals.global.plattypus.co.uk www.seals.global.plattypus.co.uk seals.global www.uzimate.com uzimate.com jardimgomes.pt www.gestionale.istitutoelveticodigaranzia.ch gestionale.istitutoelveticodigaranzia.ch www.shop.megadealsom.com shop.megadealsom.com eletro4life.pt chatrog.me cruisebooking.kr bluepiel.com thebootbledlowridge.co.uk opere.cristallocostruzioni.com www.sg6copywriter.com.sg6.co.uk sg6copywriter.com.sg6.co.uk anniemac.developmentandtesting.co.uk jafrobeat.com immobilexpress.com crownstonecertification.com snacklth.com thaihousemassagebath.co.uk moneyinpodcast.com spectralma.com www.madmed.com madmed.com rzeen.ae oneonbox.com landlordfix.com alecyclingkit.com rahtek.net gspmediallc.com mybettercolors.com ka-moden.com orlandocoronado.com www.toprent-srl.com.recos.a2hosted.com toprent-srl.com.recos.a2hosted.com www.toprent-srl.com geordamis.gr.pga2.a2hosted.com geordamis.gr www.geordamis.gr.pga2.a2hosted.com www.geordamis.gr www.spalifeandmassagebandstead.co.uk spalifeandmassagebandstead.co.uk surfmax.es www.surfmax.es immobilcredit.com www.immobilcredit.com gorillalodgingrwanda.com mail.dexcelencia.com autodiscover.dexcelencia.com cpanel.dexcelencia.com antenacrista.com jobsearchrecruit.com nextcitystop.com sigalaswood.pga2.a2hosted.com www.sigalaswood.gr sigalaswood.gr www.sigalaswood.pga2.a2hosted.com www.testsite.oconnellsflorists.co.uk testsite.oconnellsflorists.co.uk moffattheatre.co.uk.araripe.clothing www.moffattheatre.co.uk www.moffattheatre.co.uk.araripe.clothing moffattheatre.co.uk cpanel.aimaggie.com aimaggie.com webdisk.seomaggie.com yasdomain.website www.yasdomain.website click2sale.co.il test.pollopo.com click2sale.co.il.pollopo.com www.test.pollopo.com www.click2sale.co.il art.ai www.digitalwebsoftware.blackcat.a2hosted.com digitalwebsoftware.blackcat.a2hosted.com www.plumber-one.com plumber-one.com www.iso9001certificates.co.za iso9001certificates.co.za globalnonwovens.com www.giffgaff-sim-only-deals.com wvlimpeza.pt www.megadealsom.com.grandsouq.ae megadealsom.com.grandsouq.ae www.megadealsom.com www.segmed.com segmed.com www.giacomo-focardi.com www.blandineanderson.com stream.bluepiel.com www.stream.bluepiel.com vankus.com www.vankus.com firstweek.allmediagh.com www.deliveryalert.allmediagh.com www.firstweek.allmediagh.com deliveryalert.allmediagh.com clientmeetings.allmediagh.com www.clientmeetings.allmediagh.com www.hr.allmediagh.com hr.allmediagh.com dimensao-aclamada.pt www.dimensao-aclamada.pt www.daisi.org.uk daisi.org.uk matgar.online medaja.com www.testsms.allmediaghsms.com testsms.allmediaghsms.com www.florencehealthcare.international florencehealthcare.international mindfulmeditationportal.com www.hibatrainingcenter.com www.amigovagabundoteatro.com sistainable.co.uk rep.uxpan.net www.rep.uxpan.net a2test.uygunahsap.com www.a2test.uygunahsap.com perfumesofthepast.nl www.thepicklemaster.com thepicklemaster.com www.tsalopoulos.com.gr tsalopoulos.com.gr www.tobiastobiastobias.com epica-awards-aije.com.scienceprod.com www.epica-awards-aije.com.scienceprod.com nidafarid.com autodiscover.aviationfrace.gr www.cruiselive.com.cruise.a2hosted.com www.cruiselive.com cruiselive.com cruiselive.com.cruise.a2hosted.com autodiscover.hunicdesignsisters.com.hr autodiscover.sitey.io sfc.mycustom.page ckre.developmentandtesting.co.uk protocol.com www.directwagenverkopen.be directwagenverkopen.be www.queenbeemarketingai.com.pga2.a2hosted.com queenbeemarketingai.com.pga2.a2hosted.com www.marketingaihive.com.pga2.a2hosted.com www.queenbeemarketingai.com www.marketingaihive.com www.rmrvpools-solutions.pt sinteg.al voter.sigma.a2hosted.com www.voter.sigma.a2hosted.com www.alamaken.sigma-space.com.sigma.a2hosted.com alamaken.sigma-space.com.sigma.a2hosted.com www.copy.eltagir.com copy.eltagir.com stag.davidbowienews.com www.stag.davidbowienews.com staging.aleclothing.com archive.gadrrres.net www.zazeliuludbregu.rul.com.hr www.zazeliupodravini.rul.com.hr judabanquetes.com www.rijpmaschilderwerken.nl rijpmaschilderwerken.nl bus-algarve.com ifcinflow.developmentandtesting.co.uk anglonordic.developmentandtesting.co.uk andermanngroup.com.pga2.a2hosted.com autodiscover.gamenessmonster.com autodiscover.uxpan.net www.sleeptock.com www.sleeptock.com.scienceprod.com rotavdrag2012.se autodiscover.enxaquecas.pt clients.superloop.dev www.clients.superloop.dev benthomasdotnet.com boatdaytrip.es autodiscover.sigalaswood.gr www.qudurat.eltagir.com qudurat.eltagir.com clinicabonavitta.com.br www.clinicabonavitta.com.br www.timcameraman.co.uk.sg6.co.uk timcameraman.co.uk.sg6.co.uk www.timcameraman.co.uk timcameraman.co.uk cosul-fermierului.ro.nomad-developer.co.uk circularrubberplatform.com www.circularrubberplatform.com www.spalifebanstead.co.uk spalifebanstead.co.uk shortletexperts.com.bigroof.com www.shortletexperts.com.bigroof.com swarovski-crystals.com dexcelencia.com majestic.es www.majestic.es techcloudsystems.com mariawakiengenharia.com armenoidconstruction.com www.markpullen.com markpullen.com www.setwish.com www.setwish.com.homecomfortonline.co.uk setwish.com.homecomfortonline.co.uk yasaddress.live arastarabarseyr.com herecreateadvertisement.com advancetech-center.com ixoraestate.com marketingaihive.com alihassanmoosa.com connectpgleadership.com ceotpgleadership.com mailtpgleadership.com boardtpgleadership.com exectpgleadership.com autodiscover.victoriadriveways.co.uk grid2.developmentandtesting.co.uk presentx.design webprojectsupport.com.powersellerlogistics.com www.webprojectsupport.com.powersellerlogistics.com securetechsoftware.com www.byta-fonster.se app.mygrworld.com www.app.readyforguest.com tobiastobiastobias.com www.luxoredu.pendulum4solutions.com luxoredu.pendulum4solutions.com classicnutrition.nl www.taprotzan.com.innoviumdigital.ltd seomaggie.com mksinfotech.com www.rentcarcascais.com rentcarcascais.com paologrimoldi.com.terapistaperfetto.a2hosted.com www.paologrimoldi.com www.filippocapuano.com www.paologrimoldi.com.terapistaperfetto.a2hosted.com filippocapuano.com.terapistaperfetto.a2hosted.com www.filippocapuano.com.terapistaperfetto.a2hosted.com www.manuel-vergura.com.terapistaperfetto.a2hosted.com manuel-vergura.com.terapistaperfetto.a2hosted.com www.manuel-vergura.com app.readyforguest.com dawratk.com upwyde.estate www.wellbeingwitch.co.uk wellbeingwitch.co.uk www.pellets.energi-och-el.se pellets.energi-och-el.se wordpressbusinesswebsite.com webmail.ricarela.com autodiscover.amurtel.net byta-fonster.se autodiscover.ozdemirsuzuki.com destmuhendislik.com tawaf.travel wordpressglasgow.com anglo-nordic.co.uk www.anglo-nordic.co.uk helpcenter2.dadan.io www.helpcenter2.dadan.io www.cci-ioannina.gr cci-ioannina.gr cci-ioannina.gr.sgahosting01.a2hosted.com www.cci-ioannina.gr.sgahosting01.a2hosted.com www.talkbackadvicebureau.com fpc.company www.fpc.company arabassets.estate superyachtsinsurance.developmentandtesting.co.uk rlafc.com racingla.com yasdomain.cam corcehuizachal.com www.panjene.com panjene.com oplossing-online.nl www.oplossing-online.nl www.droom-veranda.nl droom-veranda.nl www.yas-rwoi.site yas-rwoi.site yas-o4vu.site www.yas-o4vu.site lygkistes.gr www.lygkistes.gr www.hasballah.pendulum4solutions.com
Malware Detected on Host
Count: 12 917e549ea2770069f590e23acee7619b824694a600924144c8e0a18339622e51 96c0d2f042beae648cb721d2fd43beaf9b5762a641c3d5478e58db8d43b6ab97 8a6ac6aaa8fc029258663745116c13cca87510688a62134f4f580e5e221d6997 4b49ff02c3b61720ba557fd17b738ee559924ecc067c42d7d8b870e2aa732517 32947fc29580dbfc6f66a0eac6038e5374c446fb6e2b0f0c32d3d7aae7b55d8b 5ee51fa6eae9a9939cae60f7a3282888067054b1c8c286a5e669d16e9dd3a9d7 d8bab454c5692de5de9ae60b38c2142a7a9202525ecc88e18708a0de646dedcd f9c6fb11eb71bdda6761b6273501c637a30e2d2f29edb6cb8a1aa1319275833b 32d96ae58fa7178e8f5484d93d656c213872f4848027601703d228e265c8e626 fdee3e0b517f6662b1afef92eaccf0b65fddf4be42cffd736e61181aa1bfa707
Open Ports Detected
2079 2080 2083 2086 2087 2096 21 443 465 7822 80 993
Map
Whois Information
- NetRange: 68.66.212.0 - 68.66.255.255
- CIDR: 68.66.216.0/21, 68.66.212.0/22, 68.66.224.0/19
- NetName: INTERNET-BLK-A2HOS-13
- NetHandle: NET-68-66-212-0-1
- Parent: NET68 (NET-68-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: A2 Hosting, Inc. (A2HOS)
- RegDate: 2009-09-01
- Updated: 2020-01-07
- Ref: https://rdap.arin.net/registry/ip/68.66.212.0
- OrgName: A2 Hosting, Inc.
- OrgId: A2HOS
- Address: P.O. Box 2998
- City: Ann Arbor
- StateProv: MI
- PostalCode: 48106
- Country: US
- RegDate: 2004-03-16
- Updated: 2025-11-11
- Comment: http://www.a2hosting.com
- Ref: https://rdap.arin.net/registry/entity/A2HOS
- OrgTechHandle: NETWO10018-ARIN
- OrgTechName: Networks
- OrgTechPhone: +15182186040
- OrgTechEmail: networks@hosting.com
- OrgTechRef: https://rdap.arin.net/registry/entity/NETWO10018-ARIN
- OrgAbuseHandle: CONTA420-ARIN
- OrgAbuseName: Contact, Abuse
- OrgAbusePhone: +442030954275
- OrgAbuseEmail: abuse@hosting.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/CONTA420-ARIN
- OrgTechHandle: DAVEY24-ARIN
- OrgTechName: Davey, Michael
- OrgTechPhone: +44 20 30954278
- OrgTechEmail: michael@worldhost.group
- OrgTechRef: https://rdap.arin.net/registry/entity/DAVEY24-ARIN