45.91.64.6 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 45.91.64.6 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 55/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Spain
  • Noticed: 50 times
  • Protocols Attacked: portscan redis
  • Countries Attacked: United States of America
  • Tor Node: No

Tags

  • 2026-01
  • 2026-02
  • Adbhoney
  • attack
  • Automated
  • auto-updated
  • blocked-ips
  • botnet
  • bruteforce
  • cisco
  • conpot
  • cowrie
  • database
  • digital ocean
  • dionaea
  • dugganusa
  • elasticpot
  • email
  • fatt
  • github
  • heralding
  • honeytrap
  • infostealer
  • isp-reputation
  • LAMP
  • login
  • mailoney
  • malicious
  • mitre-attack
  • OpenCTI
  • p0f
  • pattern-32
  • pattern-38
  • portscan
  • rce
  • redis
  • Redisreplication
  • rhadamanthys
  • scanner
  • scanners
  • sensor-tagged
  • sentrypeer
  • sftp
  • sip
  • ssh
  • SSH
  • ssl-enrichment
  • stealc
  • stix-2.1
  • supply-chain
  • #supportsitewebsiteabuse #rootcertificatefailure #cryptographicf
  • suricata
  • tanner
  • telnet
  • Telnet
  • The dynamics of the mudoSOSIntersectalign with sophisticated adv
  • threat-intelligence
  • tpot
  • vultr

MITRE ATT&CK TTPs

  • T1005 - Data from Local System
  • T1016 - System Network Configuration Discovery
  • T1027 - Obfuscated Files or Information
  • T1033 - System Owner/User Discovery
  • T1036.006 - Space after Filename
  • T1057 - Process Discovery
  • T1059.001 - PowerShell
  • T1059.004 - Unix Shell
  • T1070.004 - File Deletion
  • T1071.001 - Web Protocols
  • T1071 - Application Layer Protocol
  • T1078 - Valid Accounts
  • T1082 - System Information Discovery
  • T1083 - File and Directory Discovery
  • T1090 - Proxy
  • T1102 - Web Service
  • T1110 - Brute Force
  • T1140 - Deobfuscate/Decode Files or Information
  • T1195.002 - Compromise Software Supply Chain
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1555.003 - Credentials from Web Browsers
  • T1555 - Credentials from Password Stores
  • T1573 - Encrypted Channel
  • T1583.006 - Web Services
  • T1585 - Establish Accounts
  • T1586 - Compromise Accounts
  • T1595 - Active Scanning

Passive DNS

  • www.pruebas.powerlinedesign.es

Attack Log References

Whois Information

inetnum: 45.91.64.0 - 45.91.64.255 descr: F6 netname: RU-TOPTELECOM-20190626 country: RU org: ORG-TL905-RIPE admin-c: AA43330-RIPE tech-c: AA43330-RIPE status: ALLOCATED-ASSIGNED PA mnt-by: TTK-MNT mnt-by: RIPE-NCC-HM-MNT created: 2024-07-24T11:54:12Z last-modified: 2025-12-18T08:08:54Z abuse-c: AH15420-RIPE organisation: ORG-TL905-RIPE org-name: TopTeleCom LLC country: RU org-type: LIR address: Marshala Rybalko st., 2, k.6 address: 123060 address: Moscow address: RUSSIAN FEDERATION phone: +7 495 147-0370 admin-c: AA43330-RIPE tech-c: AA43330-RIPE abuse-c: AR75721-RIPE mnt-ref: TTK-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: TTK-MNT created: 2024-06-03T10:50:22Z last-modified: 2024-06-03T10:50:22Z role: admin-c address: RUSSIAN FEDERATION address: Moscow address: 123060 address: Marshala Rybalko st., 2, k.6 phone: +7 495 147-0370 nic-hdl: AA43330-RIPE mnt-by: TTK-MNT created: 2024-06-03T10:50:21Z last-modified: 2024-06-03T10:50:21Z route: 45.91.64.0/24 origin: AS214664 mnt-by: TTK-MNT created: 2025-07-30T09:31:30Z last-modified: 2025-07-30T09:31:30Z