172.64.149.28 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 172.64.149.28 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 5/100

Host and Network Information

  • Tags: tsec

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network: AS13335 cloudflare
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy
  • Passive DNS Results: www.kmarket4.com courses.nickdome.com deimo.jp www.centrafin.co.za centrafin.co.za www.lyllocasino.com www.nickdome.com www.mmuldorfqa.com www-uat.testgobsn.com www-cit.testgobsn.com www-vnp.testgobsn.com sch13.sacloudpoint.net scs14.sacloudpoint.net scs13.sacloudpoint.net hls12cf.sacloudpoint.net sls11cf.sacloudpoint.net sls10cf.sacloudpoint.net hls14cf.sacloudpoint.net hls15cf.sacloudpoint.net sls3cf.sacloudpoint.net sls15cf.sacloudpoint.net hls18cf.sacloudpoint.net sls2cf.sacloudpoint.net sls5cf.sacloudpoint.net hls17cf.sacloudpoint.net hls6cf.sacloudpoint.net hls3cf.sacloudpoint.net hls16cf.sacloudpoint.net hls10cf.sacloudpoint.net sls16cf.sacloudpoint.net hls2cf.sacloudpoint.net hls11cf.sacloudpoint.net hls13cf.sacloudpoint.net sls4cf.sacloudpoint.net sls8cf.sacloudpoint.net sls17cf.sacloudpoint.net sls7cf.sacloudpoint.net sls6cf.sacloudpoint.net hls5cf.sacloudpoint.net hls4cf.sacloudpoint.net sls18cf.sacloudpoint.net hls7cf.sacloudpoint.net hls8cf.sacloudpoint.net www.optimizelystaging.com cm.wwwtest.optimizelystaging.com scs10.sacloudpoint.net sch3.sacloudpoint.net scs12.sacloudpoint.net sch1.sacloudpoint.net scs3.sacloudpoint.net sch8.sacloudpoint.net sch4.sacloudpoint.net scs8.sacloudpoint.net sch6.sacloudpoint.net scs4.sacloudpoint.net scs9.sacloudpoint.net scs2.sacloudpoint.net sch10.sacloudpoint.net scs5.sacloudpoint.net scs7.sacloudpoint.net sch2.sacloudpoint.net sch12.sacloudpoint.net scs11.sacloudpoint.net scs1.sacloudpoint.net diabetescontacto.com.co mbclinic.com blue7979.com lyllocasino.com lancomelearning.com www.poltronafrau.com www.poltronafrau.com.cdn.cloudflare.net www.ttrfap-erkennen.de ttrfap-erkennen.de

Open Ports Detected

2052 2082 2087 80 8443

Map

Whois Information

  • NetRange: 172.64.0.0 - 172.71.255.255
  • CIDR: 172.64.0.0/13
  • NetName: CLOUDFLARENET
  • NetHandle: NET-172-64-0-0-1
  • Parent: NET172 (NET-172-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS13335
  • Organization: Cloudflare, Inc. (CLOUD14)
  • RegDate: 2015-02-25
  • Updated: 2021-05-26
  • Comment: All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
  • Ref: https://rdap.arin.net/registry/ip/172.64.0.0
  • OrgName: Cloudflare, Inc.
  • OrgId: CLOUD14
  • Address: 101 Townsend Street
  • City: San Francisco
  • StateProv: CA
  • PostalCode: 94107
  • Country: US
  • RegDate: 2010-07-09
  • Updated: 2021-07-01
  • Ref: https://rdap.arin.net/registry/entity/CLOUD14
  • OrgNOCHandle: CLOUD146-ARIN
  • OrgNOCName: Cloudflare-NOC
  • OrgNOCPhone: +1-650-319-8930
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
  • OrgAbuseHandle: ABUSE2916-ARIN
  • OrgAbuseName: Abuse
  • OrgAbusePhone: +1-650-319-8930
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
  • OrgRoutingHandle: CLOUD146-ARIN
  • OrgRoutingName: Cloudflare-NOC
  • OrgRoutingPhone: +1-650-319-8930
  • OrgRoutingEmail: [email protected]
  • OrgRoutingRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
  • OrgTechHandle: ADMIN2521-ARIN
  • OrgTechName: Admin
  • OrgTechPhone: +1-650-319-8930
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
  • RAbuseHandle: ABUSE2916-ARIN
  • RAbuseName: Abuse
  • RAbusePhone: +1-650-319-8930
  • RAbuseEmail: [email protected]
  • RAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
  • RTechHandle: ADMIN2521-ARIN
  • RTechName: Admin
  • RTechPhone: +1-650-319-8930
  • RTechEmail: [email protected]
  • RTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
  • RNOCHandle: NOC11962-ARIN
  • RNOCName: NOC
  • RNOCPhone: +1-650-319-8930
  • RNOCEmail: [email protected]
  • RNOCRef: https://rdap.arin.net/registry/entity/NOC11962-ARIN

Links to attack logs

anonymous-proxy-ip-list-2023-06-22