64.34.156.168 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 64.34.156.168 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 47/100
Host and Network Information
-
Mitre ATT&CK IDs: T1010 - Application Window Discovery, T1012 - Query Registry, T1018 - Remote System Discovery, T1027 - Obfuscated Files or Information, T1036 - Masquerading, T1040 - Network Sniffing, T1045 - Software Packing, T1047 - Windows Management Instrumentation, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1057 - Process Discovery, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1068 - Exploitation for Privilege Escalation, T1071 - Application Layer Protocol, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1095 - Non-Application Layer Protocol, T1098 - Account Manipulation, T1105 - Ingress Tool Transfer, T1112 - Modify Registry, T1125 - Video Capture, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1143 - Hidden Window, T1158 - Hidden Files and Directories, T1210 - Exploitation of Remote Services, T1414 - Capture Clipboard Data, T1428 - Exploit Enterprise Resources, T1490 - Inhibit System Recovery, T1497 - Virtualization/Sandbox Evasion, T1510 - Clipboard Modification, T1512 - Capture Camera, T1518 - Software Discovery, T1529 - System Shutdown/Reboot, T1562 - Impair Defenses, T1564 - Hide Artifacts, T1566 - Phishing, T1571 - Non-Standard Port, T1573 - Encrypted Channel, T1574 - Hijack Execution Flow, T1583.005 - Botnet, T1614 - System Location Discovery, TA0011 - Command and Control
-
Tags: 1 upx1, aaaa, accept, accept encoding, access denied, active, active file, activity, added active, address, address virtual, admin, a domains, age2592000 path, aitm, alerts, alf features, algorithm, a li, all scoreblue, apache, as13768 aptum, as15169 google, as16625 akamai, as20940, as21499 host, as2914 ntt, as29873, as31898 oracle, as3257 gtt, as35994 akamai, as396982 google, as397240, as397241, as4230 claro, as44273 host, as45102 alibaba, as47748 daticum, as62597 nsone, as8068, as8075, asn as8068, asnone bulgaria, asnone canada, asnone germany, august, authentihash, author avatar, av detections, aws, aws botnet, b59bn timestamp, b715, binary, body, body length, botnet, brendan coates, brian sabey, bruter cnc, cab null, ca issuers, calls, canada, canada unknown, cape, certificate, checkin, china, click, cname, code, commerce cloud, compiler, config, contacted, contact phone, content, contentlength, content type, copy, create c, created, createdate, creation date, c request, critical, currently, cus lsan, cyber attack, daley, data, data redacted, date, date hash, december, default, delete c, delphi, denver, denver co, detections file, discovery, div div, div li, dnssec, domain, downloads, dynamic, eastman kodak, easyshare, email, emails, encrypt, entries, et malware, evasion ta0005, execution, expiration date, explorer, false, fcolorffffff, february, filehash, filehashmd5, filehashsha1, filehashsha256, files, file samples, files domain, file size, files location, files matching, file type, final url, flag united, format, france, generic, germany, get http, ghostscript, gmt etag, gmt max, gmtn, gmt server, gobrut, gobrut malware, gtmkj5bfwx, guloader, hackers, hallrender, headers, high, hijack, historical ssl, hong kong, hosting, hostname, hostpapa, html, html info, http, http performs, http response, https, icmp traffic, idlinea8 sep, ids, imphash, im unaware, information, info sections, inhibit system, injection, install, intel, invalid url, ip address, ipv4, ja3s, kb body, kodak, kodak easyshare, kukacka, langchinese, level 3, lhangzhou, link, linux x8664, li ul, local, location united, log id, magic pe32, malware, malware c, malware config, markmonitor, may sleep, md5 chi2, md5 process, media center, medium, meta, meta http, meta tags, microsoft color, mitm, mitre att, moved, mozilla, msft, msie, ms windows, mtb dec, name, namecheap, name file, name servers, name type, name virtual, net1, next, november, ns nxdomain, number, nxdomain, oalibaba, object, october, odigicert inc, oglobalsign, oracle, overview ip, packer, passive dns, path, pecompact, persistence, photolan, please, pnpd5d, post http, pragma, pre crime, quantum fiber, quantumfiber, quantumfiber.com, rdds service, read c, record, record value, ref b, referrer, regbinary, regdword, registrant, registrar, registrar abuse, registrar iana, registrar url, registrar whois, regsetvalueexa, regsetvalueexw, regsz, related nids, related pulses, related tags, report spam, research group, rich pe, role title, round, rsdsr7siwwd d, sales, salitiy, sample, sandbox evasion, scan endpoints, script domains, search, server, server ca, servers, service, serving ip, set cookie, sha256, show, showing, singapore, sitegg, size entropy, size raw, slcc2, soa nxdomain, spotify artists, sqlite, sqlite version, ssdeep, ssh attacker, status, status code, stzhejiang, subject, suricata, susp, sysinternals, t1010, t1012, t1027, t1036 creates, t1055, t1057, t1059, t1497, tag manager, tags, target tsara brashears, tech contact, tech id, text, threat roundup, timestamp, tlsv1, tls web, tracker, trackers google, traditional, trent wiltshire, trid upx, trojan, trojan features, twitter, ubuntu, united, united kingdom, unix, unix malware, unknown, upx0, upx2, upx software, url http, url https, urls, utc facebook, utc gtm5z5w687v, utc gtmp4hkt96, utc na, vhash, virtool, virus, vt graph, wed may, west domains, whitelisted ip, win16 ne, win32, win32 exe, windows, windows nt, worm, wow64, write, write c, xa10629, xo544, xport, yara detections, zenbox
-
View other sources: Spamhaus VirusTotal
- Country: Canada
- Network:
- Noticed: 1 times
- Protocols Attacked: SSH
- Passive DNS Results: elementallifestyle.com inspectionfossesseptiques.com fosseseptiquematha.com chair-exercises.com fosseseptiqueterrebonne.com www.amazigh.ixfbox.com amazigh.ixfbox.com alhambra19.com cleanallcleaningservice.ca entrepotsalouer.com flowerbossacademy.com mesamoldremoval.pro qadigitaldesigns.com escaladedebloc.com watzup.ca crestwoodmusic.ca happiness-furniture.com www.fixerman.ca.woodexcabinet.ca fixerman.ca www.inistaller.ca.woodexcabinet.ca inistaller.ca example.nidhiprajapati.ca dj.musicmusic.ca kawarthacharityriders.ttkc.ca djaudit.musicmusic.ca lessons.musicmusic.ca talent.musicmusic.ca cedarspoon.com www.cedarspoon.com.cedarspoon.ca cedarspoon.com.cedarspoon.ca transitionvegetale.ca www.labwyze.ellicode.com inspectionfosseseptiquelaurentides.com goews.xyz www.webdesign19.com.benmohammed.com webdesign19.com.benmohammed.com escaperealestate.ca escaperealestate.ca.elementallife.ca www.escaperealestate.ca.elementallife.ca sutco.ca.thesutherland.group sutco.ca www.sutco.ca.thesutherland.group winnieflower.com starprodigital.ca www.starprodigital.ca.sproinspections.ca starprodigital.ca.sproinspections.ca www.flowerbossmasterclass.littlebirdbloom.ca flowerbossmasterclass.littlebirdbloom.ca www.entretienfosseseptique.com.santeoptimale.ca entretienfosseseptique.com.santeoptimale.ca www.haywardhealth.ca haywardhealth.ca www.anythinggoodabouthell.dirksfamily.ca www.womanmeanssomething.dirksfamily.ca anythinggoodabouthell.com dirksfamily.ca tracysmitten.com www.test.tracysmitten.com melaninunderground.ca.tracysmitten.com www.melaninunderground.ca.tracysmitten.com cotolansfencing.ca www.cotolansfencing.ca.myaccountium.ca cotolansfencing.ca.myaccountium.ca parnodrom.koroentertainment.com regencycleaners.ca www.gtawoodworks.com www.ultrasonicblinds.ca www.interactive.nidhiprajapati.ca interactive.nidhiprajapati.ca www.canteach.ca katrinabolletta.com.kysocreative.com www.katrinabolletta.com.kysocreative.com elementallifestyle.ca ppc-hamilton.ca www.flowerbossformula.com.littlebirdbloom.ca flowerbossformula.com.littlebirdbloom.ca flowerbossformula.com cpcontacts.europeantime.com cpcalendars.europeantime.com bceco.ca staging.kysocreative.com littlebirdbloom.com marcusdupuis.com.elementallife.ca marcusdupuis.com www.marcusdupuis.com.elementallife.ca www.britishdetectivestories.com.gameplanmedia.ca britishdetectivestories.com www.britishdetectivestories.com britishdetectivestories.com.gameplanmedia.ca ecgoc.ca.bow34.ca www.ecgoc.ca.bow34.ca ecgoc.ca seekfor.net cpappers.com www.formations.msasmali.org archive.rolfinginottawa.com www.archive.rolfinginottawa.com kankoucapital.com womanmeanssomething.com entelizence.com.entelizence.ca www.entelizence.com.entelizence.ca ircdette.com mirrormansaga.dirksfamily.ca www.mirrormansaga.dirksfamily.ca ogwadenideotco.org summer.net-zero-plus.com www.summer.net-zero-plus.com fossesseptiqueslanaudiere.com collettemachinery.sunwebsolutions.com www.collettemachinery.sunwebsolutions.com workjaz.ca www.parklandbeachblog.ca.jazzie.ca www.workjaz.ca.jazzie.ca parklandbeachblog.ca ray.nidhiprajapati.ca www.zoom.svetmiru.ca zoom.svetmiru.ca mountaingoatfitness.ca www.markpjnadon.mountaingoatfitness.ca markpjnadon.ca www.omnifitness.ca.mountaingoatfitness.ca www.soldiersoffitnessottawa.mountaingoatfitness.ca omnifitness.ca omnifitnessottawa.ca www.soldiersoffitnessottawa.ca.mountaingoatfitness.ca soldiersoffitnessottawa.mountaingoatfitness.ca www.omnifitnessottawa.ca.mountaingoatfitness.ca design.nortoncam.com www.design.nortoncam.com jenniferf.ca.sylviamcnicoll.com www.jenniferf.ca.sylviamcnicoll.com www.rvfrna.pittmeadowsgardenclub.ca rvfrna.pittmeadowsgardenclub.ca cagedangelfilms.com.submicronresearch.com www.cagedangelfilms.com.submicronresearch.com cagedangelfilms.com www.pcbtech.ixfbox.com pcbtech.ixfbox.com www.simpliifunded.com.libertysecurityusa.us simpliifunded.com www.finicons.com.intrepidmedtech.com www.hotelheranyala.com.intrepidmedtech.com www.powertool.school.theemailcompany.com powertool.school.theemailcompany.com www.site2.antoniosotogoogle.ca www.site3.antoniosotogoogle.ca www.site5.antoniosotogoogle.ca www.site1.antoniosotogoogle.ca www.site4.antoniosotogoogle.ca alphachallenge.ca alphachallenge.ca.ttkc.ca www.alphachallenge.ca.ttkc.ca storytellerstudio.ca www.sstarslive.com digivelop.ca jewelleryecommerce.quratulann.ca www.jewelleryecommerce.quratulann.ca agilikmovement.com.bionic-power.com www.agilikmovement.com.bionic-power.com agilikmovement.com ultimaclinic.ca.ultimapharmacy.ca ultimaclinic.ca www.ultimaclinic.ca.ultimapharmacy.ca www.powerjetcleaners.com.dowimprovements.com powerjetcleaners.com.dowimprovements.com findwellnesssolution.com.santeoptimale.ca www.findwellnesssolution.com.santeoptimale.ca www.collettemachinery.com powertool.school rolfottawa.ca www.rolfottawa.ca.rolfinginottawa.com rolfottawa.ca.rolfinginottawa.com wellmanfenceland.ca www.lmdroof.ca www.site6.antoniosotogoogle.ca site6.antoniosotogoogle.ca soccerkent.sunwebsolutions.com www.soccerkent.sunwebsolutions.com www.vcglobal.ca.green-nature.org vcglobal.ca.green-nature.org notsomedia.com.domepans.com www.notsomedia.com.domepans.com lisha.mach2.ca www.lisha.mach2.ca www.elementalprefab.com.elementallife.ca elementalprefab.com.elementallife.ca stoneandhammer.ca www.restaurantkaram.com.benmohammed.com restaurantkaram.com.benmohammed.com dashboard.insight-fx.com www.dashboard.insight-fx.com woodexcabinet.ir www.woodexcabinet.ir.woodexcabinet.ca woodexcabinet.com.woodexcabinet.ca www.woodexcabinet.com.woodexcabinet.ca woodexcabinet.ir.woodexcabinet.ca mojomotstranslation.ca toilesmagistral.com murrayellis.ca dikaloservices.ca www.theeshack.net.ttkc.ca theeshack.net theeshack.net.ttkc.ca zuserbilisim.kingswaymedical.ca www.zuserbilisim.kingswaymedical.ca entretienfosseseptique.com entreprisediali.com vrduproprio.com jeuantistress.com notsomedia.com webdesign19.com climate-guard.org daychem.net finicons.com hotelheranyala.com woodexcabinet.com eli-mak.com restaurantkaram.com benmohammed.com thepatchoutfitters.ca sql.yourpets.ca www.sql.yourpets.ca ecmcpa.ca ecmcpa.ca.ecmcpa.com www.ecmcpa.ca.ecmcpa.com europeantime.com zoroastrian-religion.ca wedvenuequest.com findwellnesssolution.com moxies-redo.jrdnthedev.com www.moxies-redo.jrdnthedev.com actualitesplus.com soccerkent.ca caribbeanseacharter.com anthonyrecoverycoach.com marianareyesimmobilier.com bien-etre.blog www.hds.typicyl.com www.hollowdreamstudios.typicyl.com phototaime.com elementalprefabs.com elementalprefab.com anomalousbehaviour.com mypost.typicyl.com www.mypost.typicyl.com www.pod.mlnet.ca pod.mlnet.ca santeoptimale.ca thirdcenturyofmedicine.net www.thirdcenturyofmedicine.net.https---macafeine.ca thirdcenturyofmedicine.net.https—macafeine.ca www.thirdcenturyofmedicine.net illuminatedsacredgeometry.com powerjetcleaners.com whospitality.ca windermerehospitality.ca www.company-page.zihsilva.com company-page.zihsilva.com manialytique.com uppereastunionville.com agileinstories.com.philosofical.com www.agileinstories.com.philosofical.com agileinstories.com www.algerienetwork.sitewebdiali.com algerienetwork.com algerie-network.com www.algerie-network.sitewebdiali.com subscribe.wmspace.ca www.subscribe.wmspace.ca www.marinestore.zihsilva.com www.marine.zihsilva.com avery.vincentge.com www.avery.vincentge.com www.aapaintinglethbridge.com dev.amyclark.ca www.dev.amyclark.ca atu1722.ca chickadeehillsfarm.ca www.teachoice.kitsolutions.ca lms.francoisapril.ca www.lms.francoisapril.ca morehuman.heylon.ca morehuman.ca www.morehuman.heylon.ca new.paolorinaldidesign.com agencewebsfl.ca labwyze.com staging.westshoreswapshop.ca www.staging.westshoreswapshop.ca www.images.moneyandfinancialfreedom.com images.moneyandfinancialfreedom.com mh-staging-june-2023.motionhouse.ca www.mh-staging-june-2023.motionhouse.ca cybersavvy.ca www.thesaucysergeant.craftedpint.ca thesaucysergeant.craftedpint.ca tektonrenovations.com www.caretransport2.umanbase.com www.caretransport.umanbase.com caretransport.ca dtales.ca www.talkytags.ca talkytags.ca urstruly.ca flowerbossmasterclass.com frostbite.beer dirtyspoons.hodgegames.com calgaryivf.com ctatiana.wmspace.ca www.ctatiana.wmspace.ca ircdette.ca ircdette.sitewebdiali.com www.scbgsnew.coastbotanicalgarden.org peakkinesiology.com ndtltsd.ca shreejisteeltech.vproduction.ca www.shreejisteeltech.vproduction.ca www.accessibility.geomate.ca marksmaninvest.ca jamesrha.com www.test9.antoniosotogoogle.ca www.test8.antoniosotogoogle.ca patrickwilliamsmortgages.ca daily-post.com www.artgothe.sitewebdiali.com shampoingexpert.ca www.shampoingexpert.sitewebdiali.com www.ircdette.sitewebdiali.com artgothe.ca www.kaatzacathotel.gameplanmedia.ca www.gpmsitedevelopment1.gameplanmedia.ca kaatzacathotel.ca gpmsitedevelopment.ca www.i-mend.testwebs.ca i-mend.testwebs.ca newleads.attaininsight.com uhillpac.com spicywebdev.com www.cpalink.myaccountium.ca www.accountanthq.myaccountium.ca cpalink.ca accountanthq.ca alithospitality.com smithandsmithgallery2.mikesmith.ca www.internal.thesutherland.group internal.thesutherland.group djrmedia.ca www.online.smithandsmithgallery.com online.smithandsmithgallery.com by-tech.ca www.unixhq.com.my-emergency-plumber.com unixhq.com.my-emergency-plumber.com www.test.canna-canada.ca test.canna-canada.ca www.test2.antoniosotogoogle.ca www.test3.antoniosotogoogle.ca www.test1.antoniosotogoogle.ca www.test4.antoniosotogoogle.ca www.test5.antoniosotogoogle.ca ebanistart.com www.project.singharshdeep.design project.singharshdeep.design nominations.forassociations.com www.nominations.forassociations.com staging.smithandsmithgallery.com www.staging.smithandsmithgallery.com gtalook4goods.ca www.gtalook4goods.theracquets.ca collettemachinery.com www.brain-tms.mahdialavi.com www.tmsiofit.mahdialavi.com motionhouse.ca www.formationdiali.sitewebdiali.com dev.bagelplus.ca www.dev.bagelplus.ca battikhasecurity.libertysecurityusa.us lifearrangements.ca realtoriq.co realtoriqco.townspace.ca www.realtoriqco.townspace.ca quillseditions.com www.quillseditions.sitewebdiali.com www.erepairs.dorbinar.ca erepairs.dorbinar.ca erepairs.ca interiordesignbookkeeping.ca thesutherland.group www.canasta.cookie87.ca canasta.cookie87.ca lamachineadonner.montrealgivingmachine.ca lamachineadonner.ca www.lamachineadonner.montrealgivingmachine.ca expat-canada.ca coalitions.ca flowerdeco.ca mpicareers.ca rockyrmt.com www.rockyrmt.tenthousandtherapy.ca rockyrmt.tenthousandtherapy.ca www.ar.singharshdeep.design bespoketech.ca www.misti.iplusplustech.com misti.iplusplustech.com misti.ca jawsdrama.ca icanandiwill.ca opendoorchurchmontreal.com www.manageclient.excepticon.ca manageclient.excepticon.ca www.owa.livromaniac.com dev.cvappros.com northstargrantmanagement.com www.theo.singhgurpinder.ca www.ray.singhgurpinder.ca www.daoandyoga.chunmiaowu.com daoandyoga.chunmiaowu.com daoandyoga.com www.host.jaspreetsinghs.com thesacredhouse.ca ecommerce.zihsilva.com www.ecommerce.zihsilva.com malayalamayooram.bramptoncouncil.org www.game.singharshdeep.design www.arges-design.argesdesign.ca timelyfeasts.com www.xiezuo.bisai.ca www.yanjiang.bisai.ca canadaforfree.ca master.graphics www.master.autogloss.ca master.autogloss.ca stratejconstructions.com 3wcollegeca.360job.com willowwalk.ca www.rellusion.royamansoorvar.com www.rellusion1.royamansoorvar.com rellusion.com rellusion.ca van01.360job.com opticalrepublic.ca coadybustin.ca livromaniac.com portfolio.badlilkiddo.ca www.portfolio.badlilkiddo.ca th3happyflamingo.ca www.staging.thesacredhouse.ca staging.thesacredhouse.ca www.twistedcojones.com ve7fvw.ca athenatantra.ca www.test.renepaul.net test.renepaul.net jackxue.com automatwhiterabbit.com elumind.ca elumind.elumind.com www.staging.kcdrilling.ca staging.kcdrilling.ca canadafertility.fertilecalgary.com thefrequencyfarm.ca culletenvironmental.ca angelinathorne.relativetous.com www.allerganbrandbox.ca allerganbrandbox.ca youngandwellness.com www.renewables.net-zero-plus.com www.kwh.net-zero-plus.com net-zero-plus.com www.judging.forassociations.com judging.forassociations.com yongewellness.com watertang.ca www.condodash.ca condodash.ca soutiencsn.com www.calgarychiropractic.fertilecalgary.com calgarychiropractic.ca calgarychiropractic.fertilecalgary.com skip.cookie87.ca bulanu.artpro-design.com emveemanagement.com canadianphotography.ca byparts.ca cashmoneynews.net cashmoneynews.townspace.ca www.cashmoneynews.townspace.ca happyheartspreschool.ca www.pelvicfloorcalgary.fertilecalgary.com prenatalchiropractic.ca naturopathcalgary.ca www.prenatalyogacalgary.fertilecalgary.com pelvicfloorcalgary.com www.naturopathcalgary.fertilecalgary.com prenatalyogacalgary.com prenatalmassagecalgary.ca dakotagammel.ca douglasjricketts.com qestmanagementconsulting.ca swintheassembly.ca www.canadianharvester.hookedmagazine.ca
Map
Whois Information
- NetRange: 64.34.96.0 - 64.34.255.255
- CIDR: 64.34.96.0/19, 64.34.128.0/17
- NetName: PEER1-BLK-08
- NetHandle: NET-64-34-96-0-2
- Parent: NET64 (NET-64-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Aptum Technologies (PER1)
- RegDate: 2004-07-15
- Updated: 2025-04-28
- Comment: For abuse issues please e-mail abuse@peer1.net. All
- Comment: other inquiries can be directed to support@peer1.net. Our 24 x 7 NOC is
- Comment: available at 866-484-2588
- Ref: https://rdap.arin.net/registry/ip/64.34.96.0
- OrgName: Aptum Technologies
- OrgId: PER1
- Address: 191 The West Mall
- City: Etobicoke
- StateProv: ON
- PostalCode: M9C 5L6
- Country: CA
- RegDate:
- Updated: 2023-08-09
- Ref: https://rdap.arin.net/registry/entity/PER1
- OrgTechHandle: APTUM-ARIN
- OrgTechName: Aptum Technologies
- OrgTechPhone: +1-866-484-2588
- OrgTechEmail: nsc.global@aptum.com
- OrgTechRef: https://rdap.arin.net/registry/entity/APTUM-ARIN
- OrgAbuseHandle: ATAE-ARIN
- OrgAbuseName: Aptum Technologies AUP Enforcement
- OrgAbusePhone: +1-678-365-2835
- OrgAbuseEmail: abuse@aptum.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/ATAE-ARIN
- RNOCHandle: ZP55-ARIN
- RNOCName: PEER 1 Network Inc
- RNOCPhone: +1-866-484-2588
- RNOCEmail: nsc.global@aptum.com
- RNOCRef: https://rdap.arin.net/registry/entity/ZP55-ARIN