How do I find out on info on an IP address?

CrazyHelloDeli

Platinum Member
Jun 24, 2001
2,854
0
0
66.35.229.200:80 http

I have this connection constantly whenever I run netstat -a, but have no information on who or where its coming from. Its always a connection from a random port on my side to port 80 on this address. Ive run my own port and vulnerability scans on this machine and it appers to be a Linux box running apache. I suspect it might be a trojan of somesort, but Norton hasnt screamed at all. I dont know how long ive had it. How can I find out information on who this IP address administered under?

Oh and to my knowledge I have no spyware, Like Kazaa or anything.
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
reverse lookup info on that ip

Reverse Lookup Results
Host Type Value
229.35.66.in-addr.arpa NS DNS02.EXODUS.NET
229.35.66.in-addr.arpa NS DNS03.EXODUS.NET
229.35.66.in-addr.arpa NS DNS04.EXODUS.NET
229.35.66.in-addr.arpa NS DNS01.EXODUS.NET
DNS02.EXODUS.NET A 209.1.222.245
DNS03.EXODUS.NET A 209.1.222.246
DNS04.EXODUS.NET A 209.1.222.247
DNS01.EXODUS.NET A 209.1.222.244

here's some tools for more info: Link

 

geoff2k

Golden Member
Sep 2, 2000
1,929
0
76
It's gator:

%rwhois V-1.5:001ab7:00 rwhois.exodus.net (Exodus Communications)
66.35.229.200
network:Class-Name:network
network:Auth-Area:0.0.0.0/0
network:Network-Name:66.35.229.0
network:IP-Network:66.35.229.0/24
network: organization;I:The Gator Corporation
network:Street;I:2000 Bridge Parkway, Suite 100
network:City;I:Redwood City
network:State;I:CA
network: Postal-Code;I:94065
network:Country-Code;I:USA

network:Class-Name:network
network:Auth-Area:0.0.0.0/0
network:Network-Name:66.35.192.0
network:IP-Network:66.35.192.0/18
network: organization;I:Exodus IDC - SV/SC8
network:Name;I:IP Address Administrator
network:Email;I:ipaddressadmin@exodus.net
network:Street;I:2831 Mission College Blvd.
network:City;I:Santa Clara, CA 95054

Time to run ad-aware.

(small edit to remove auto-smilies)