IP Address Inspector
We don't have data on this IP currently. If you know something, you may leave a comment.
|Geographic Location||United States|
August 16 2018 09:55 AM
IP Address 18.104.22.168 is listed in the CBL. It shows signs of being infected with a spam sending trojan, malicious link or some other form of botnet.
It was last detected at 2015-09-15 19:00 GMT (+/- 30 minutes), approximately 1 hours, 30 minutes ago.
This IP address is infected with, or is NATting for a machine infected with Tinba.
Tinba (also known as "tiny banker" and "illi") is a ebanking trojan aimed to steal credentials for online banking accounts. It spreads through hijacked websites (drive-by exploits) and malicious email attachments.
The CBL detection is being made using sinkholing techniques.
This was detected by a TCP/IP connection from 22.214.171.124 on port 50738 going to IP address 126.96.36.199 (the sinkhole) on port 80.
The botnet command and control domain for this connection was "whovnyjvupxi.com".
September 15 2015 04:09 PM
Page generated on: June 01 2020 04:49:58 AM