Where we found the IP? → https://urlquery.net/report/7b1453bc-3c1f-4fa8-be13-37951c9ace91
has Crypto currency mining script → https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=c3NwfV1tXXRbXW4ufXU%3D~enc
Blacklisted → https://www.ip-tracker.org/blacklist-check.php?ip=185.165.123.50
and on another blacklist for IP: https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/hphosts_emd.ipset
On the 88 found active domains for that particular IP:
AS 64432 https://www.malware url.com/listing.php?as=active=on
polonus