184.168.221.22

Classification: Whitelisted

184.168.221.22 is a whitelisted (trusted) IP address. Reported by 13 threat sources, last seen 2026-07-23. Network: AS26496 GoDaddy.com, LLC.

Current activity

  • Hosting provider — Shared hosting infrastructure.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Hosting Provider Maltiverse 2026-07-23 09:17:24 2026-07-23 09:17:24 benign hosting
Suppobox Bambernek 2017-11-30 12:29:06 2019-04-13 06:57:57
Malicious Host APT Notes 2019-01-12 08:34:36 2019-01-12 08:34:36
Pizd Bambernek 2017-10-15 16:19:37 2018-11-25 06:49:05
Trojan.Clicker Hybrid-Analysis 2018-10-31 00:15:06 2018-10-31 00:15:06
virut Telefonica CO SOC 2018-09-30 19:10:46 2018-10-06 10:02:32
virut Maltiverse Research Team 2018-10-05 01:44:31 2018-10-05 01:44:31
Generic.Malware Hybrid-Analysis 2018-06-04 16:15:41 2018-09-12 08:00:15
Phishing Internal Revenue Service Phishtank 2018-09-01 14:32:42 2018-09-01 14:32:42
Virut Bambernek 2018-07-12 06:47:22 2018-07-12 06:47:22
Phishing Phishtank 2017-10-15 17:29:52 2018-05-28 22:57:02
Phishing Generic/Spear Phishing OpenPhish 2018-05-23 11:30:03 2018-05-23 11:30:03
virut Maltiverse 2018-04-05 11:35:27 2018-04-05 11:35:27
netsky ,worm Maltiverse 2018-03-07 13:46:56 2018-03-07 13:46:56
Phishing HSBC Bank OpenPhish 2018-03-04 20:30:05 2018-03-04 20:30:05
pony,trojan Maltiverse 2018-01-02 09:04:18 2018-01-02 09:04:18
Defacement Zone-H 2017-12-23 21:45:34 2017-12-23 21:45:34
backdoor Maltiverse 2017-12-04 04:06:14 2017-12-04 04:06:14
Matsnu Bambernek 2017-11-29 12:44:53 2017-11-29 12:44:53
banjori Bambernek 2017-11-19 13:12:17 2017-11-19 13:12:17
Spamming Alienvault Ip Reputation Database 2017-10-27 10:35:35 2017-10-27 10:35:35
banker,ransomware,shade,troldesh,tvrat,zbot Maltiverse 2017-10-18 06:12:39 2017-10-18 06:12:39
Ransomware Locky distribution site Ransomware Tracker 2017-10-15 17:51:11 2017-10-15 17:51:11
Blue Cybercrime-tracker.net 2017-10-15 14:57:28 2017-10-15 14:57:28
Inmortal malware domain Malware Domains 2017-10-15 14:45:41 2017-10-15 14:45:41

Tags

phishing netsky worm c&c c2 dga malware virut pizd https://www.threatminer.org/report.php?q=darkhydrus uses phishery to harvest credentials in the middle east - palo alto networks blog.pdf&y=2018 suppobox

Whois information

AS name
AS26496 GoDaddy.com, LLC
AS registry
arin
AS date
2010-09-21 00:00:00
AS CIDR
184.168.220.0/22
CIDR
184.168.0.0/16
Registrant
GoDaddy.com, LLC
Address
14455 N Hayden Road Suite 226
City
Phoenix
State
AZ
Postal code
85004
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected]
First indexed
2017-10-15 14:45:41
Last updated
2026-09-03 03:42:55