85.9.20.145 Fraud Risk

Very high Risk
← Lowest Risk
Highest Risk →
0
Fraud Score: 100
100
IP address ​​85.9.20.145 is operated by ​Cyberghost whose ​​web traffic we consider to present a potentially very high​ fraud risk. This IP address is owned by ​​GTS Telecom whose web traffic we also consider to present a potentially medium fraud risk. In both cases, non-web traffic may present a different risk or no risk at all. According to our most recent port scan, the IP address points to a server running the SSH server Dropbear sshd 2018.76 (protocol 2.0) on port 22. Scamalytics see high levels of traffic from Cyberghost across our global network, ​almost all of which we suspect to be potentially fraudulent. We have no visibility into the web traffic directly from ​85.9.20.145​, and therefore apply a risk score of ​100​/100 based on the overall risk from ​Cyberghost​’s IP addresses where we do have visibility. If you see web traffic from this IP address there is potentially a very high risk that it is criminals engaged in fraudulent activity. Other types of traffic may present a different risk or no risk. The device on​ 85.9.20.145 is operating ​an anonymising VPN, which could be proxying traffic from another geographical location. The geographical location of 85.9.20.145 is in Romania, however the geographical location of the user could be anywhere in the world.
IP Fraud Risk API
{
  "ip":"85.9.20.145",
  "score":"100",
  "risk":"very high"
}
        
Click here for details of our free usage tier, free trial, and pricing information.
Operator
Hostname n/a
ASN 5606
ISP Name GTS Telecom
Organization Name Cyberghost
Connection type n/a
Location
Country Name Romania
Country Code RO
Region București
City Bucuresti
Postal Code n/a
Metro Code n/a
Area Code n/a
Latitude 44.4280
Longitude 26.0966
Port Scan
TCP
22/ssh
Open
Dropbear sshd 2018.76 (protocol 2.0)
TCP
443/ssl/https?
Open
TCP
8443/https-alt
Open
nghttpx
TCP
21/ftp
Closed
TCP
113/ident
Closed
TCP
554/rtsp
Open
Apple AirTunes rtspd
TCP
995/http
Open
lighttpd
TCP
8000/ipcam
Open
Hikvision IPCam control port
TCP
8080/ssl/http
Open
Apache httpd 2.4.25 ((Raspbian))
TCP
5060/sip
Closed
TCP
88/http
Open
lighttpd 1.4.31
TCP
111/rpcbind
Open
2-4 (RPC #100000)
TCP
25/smtp
Filtered
TCP
32768/filenet-tms
Closed
TCP
49152/unknown
Closed
TCP
49153/unknown
Closed
TCP
49154/unknown
Closed
TCP
49155/unknown
Closed
TCP
49156/unknown
Closed
TCP
49157/unknown
Closed
TCP
80/http
Open
Tor built-in httpd (DirPortFrontPage configured)
TCP
8081/blackice-icecap?
Open
Proxies
Anonymizing VPN
Yes
Tor Exit Node
No
Server
No
Public Proxy
No
Web Proxy
No
Search Engine Robot
No
Domain Names
n/a

IP Address data partner DB-IP.com:

Proxy data sponsored by IP2Proxy:

IMPORTANT: Scamalytics Ltd operate a fraud-detection network with visibility into many millions of internet users per month. We do not have visibility into the entire internet. The statements on this page represent our opinion based on the limited information we have available to us, and specifically only cover web connections made by internet users to websites and applications, not other connections such as server to server connections.