64.70.19.203 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 64.70.19.203 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🔴 High Risk — 80/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Noticed: 50 times
  • Protocols Attacked: SSH
  • Countries Attacked: Afghanistan, Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Czechia, Denmark, Estonia, France, Georgia, Germany, Guatemala, Hong Kong, Ireland, Italy, Japan, Latvia, Lithuania, Mexico, Netherlands, Norway, Panama, Philippines, Poland, Romania, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Open Ports: 80
  • Tor Node: No
  • Associated Malware Samples: 198839

Tags

  • 103.129.252.44
  • 103.224.212.222
  • 103.28.36.182
  • 1575038779
  • 162.0.215.111
  • aaaa
  • aaaa nxdomain
  • abuse
  • accept
  • accept encoding
  • acint
  • activity
  • activity dns
  • acurix networks
  • added active
  • address
  • address domain
  • a div
  • adload
  • a domains
  • agent
  • agenttesla
  • akamaias
  • akamaiasn1
  • alexa
  • alexa top
  • algorithm
  • a li
  • all octoseek
  • all scoreblue
  • all search
  • amazon02
  • america
  • america asn
  • america flag
  • analysis
  • analyze
  • andromeda
  • antigua
  • a nxdomain
  • apache
  • appdata
  • apple
  • apple-access.com
  • apple phone
  • application
  • applicunwnt
  • april
  • arial helvetica
  • artemis
  • artro
  • as10906
  • as11284
  • as133618
  • as133775 xiamen
  • as13414 twitter
  • as14061
  • as15133 verizon
  • as15169
  • as15169 google
  • as16276
  • as16509
  • as17816 china
  • as19527 google
  • as206834 team
  • as20940
  • as22612
  • as24940 hetzner
  • as25825
  • as2914 ntt
  • as29873
  • as30081
  • as31034 aruba
  • as31898 oracle
  • as3359
  • as3561
  • as36459
  • as36647 oath
  • as393245 oath
  • as397240
  • as397241
  • as4134 chinanet
  • as42 woodynet
  • as44273 host
  • as46606
  • as4812 china
  • as49505
  • as53665 bodis
  • as54113
  • as54994 quantil
  • as6185 apple
  • as61969 team
  • as62597 nsone
  • as63949 linode
  • as7018 att
  • as701 verizon
  • as714 apple
  • as7296 alchemy
  • as8075
  • as852
  • as8560
  • as9009 m247
  • ascii text
  • asn as22612
  • asn as3561
  • asn as36459
  • asn as714
  • asnone
  • asnone united
  • astaroth
  • attack
  • attack bad
  • attempts
  • august
  • aurora
  • author avatar
  • auto-generated security
  • avast avg
  • ave maria
  • azorult
  • back
  • backdoor
  • bad login
  • bad request
  • bambernek
  • bandoo
  • bank
  • barbuda
  • barbuda unknown
  • basic
  • b body
  • beginstring
  • behav
  • beijing baidu
  • ben c
  • betabot
  • bios
  • bitcoinaltcoin
  • blacklist
  • blacklist http
  • blacklist https
  • bladabindi
  • bodis
  • body
  • body length
  • bq feb
  • bradesco
  • brazil unknown
  • brian sabey
  • brontok
  • browse scan
  • brute force
  • bugs
  • busybox
  • busybox busybox
  • ca execution
  • canada unknown
  • capture
  • ca validity
  • certificate
  • cgb stgreater
  • change
  • changelog
  • chaos
  • checkin
  • china
  • chrome
  • cidr
  • cisco umbrella
  • citadel
  • city
  • ck id
  • ck matrix
  • ck techniques
  • class
  • cleaner
  • click
  • clipper dos
  • cloudflarenet
  • cloud xcitium
  • cname
  • cnsectigo rsa
  • cnwe1 validity
  • cnwotrus dv
  • cobalt strike
  • code
  • code injection
  • collection
  • collisionbox
  • com laude
  • command
  • command decode
  • command type
  • communicating
  • compiler
  • computer
  • conduit
  • contact
  • contacted
  • contacted hosts
  • contacted ip
  • contacted show
  • contacted urls
  • contact phone
  • content
  • content type
  • continent na
  • control
  • cookie
  • copy
  • copy md5
  • copyright
  • copy sha1
  • copy sha256
  • core
  • country
  • country us
  • covid19
  • crack
  • crazy doll
  • create c
  • created
  • creation date
  • critical
  • critical risk
  • crlf line
  • cryp
  • crypt
  • csam
  • csc corporate
  • cuba
  • cus cnr3
  • cus ogoogle
  • cus stcolorado
  • cutwail
  • cve20170147 sep
  • cyber security
  • cyber threat
  • dark power
  • data
  • date
  • date hash
  • date sun
  • days ago
  • debug
  • default
  • defense evasion
  • delete
  • delete c
  • destination
  • detection list
  • detections
  • detections elf
  • detplock
  • digitaloceanasn
  • director
  • div div
  • div h3
  • dns intel
  • dnspionage
  • dns poisoning
  • dns replication
  • dns resolutions
  • dnssec
  • dock
  • document
  • document file
  • domain
  • domain address
  • domain http
  • domain ip
  • domain name
  • domain robot
  • domains
  • domain status
  • domaiq
  • dotcisoffer
  • downldr
  • download
  • downloader
  • downloadmr
  • dropped
  • dropper
  • drweb
  • dynamic
  • dynamicloader
  • east
  • egregor
  • elf64 crypto
  • elf info
  • email
  • email document
  • emails
  • emotet
  • emotet type
  • encrypt
  • endpoints all
  • engineering
  • enigmaprotector
  • entries
  • equiv cache
  • error
  • error all
  • error f
  • etisalat misr
  • et tor
  • executable
  • execution
  • exif data
  • exit
  • expiration
  • expiration date
  • expiresthu
  • expiry date
  • exploit
  • exploit domain
  • f2f2f2 color
  • facebook
  • fakealert
  • falcon sandbox
  • false
  • fareit
  • february
  • federation asn
  • file
  • filehash
  • filehashmd5
  • filehash sha256
  • filehashsha256
  • files
  • file samples
  • file score
  • files ip
  • files location
  • files matching
  • files related
  • filetour
  • final url
  • find
  • first
  • flag
  • flag united
  • floxif
  • footer
  • form
  • formbook
  • formbook cnc
  • for privacy
  • found
  • friendly
  • fuery
  • function
  • fusioncore
  • gamehack
  • gameoverpanel
  • gc
  • gecko
  • general
  • generator
  • generic
  • generic malware
  • genkryptik
  • geoip
  • germany
  • germany unknown
  • get response
  • ghost
  • github
  • github pages
  • global domains
  • gmt cache
  • gmt connection
  • gmt content
  • gmt contenttype
  • gmt server
  • gnu linker
  • google
  • group
  • grum
  • guard
  • hacking tools
  • hacktool
  • hack type
  • hallrender
  • hashes
  • header
  • headers
  • health type
  • helvetica neue
  • heur
  • hidden
  • hidden cobra
  • high
  • high defense
  • highly targeted
  • historical ssl
  • history first
  • host interaction
  • hostname
  • hostnames
  • hotmail
  • hsbc group
  • http
  • http method
  • httponly
  • http requests
  • http response
  • https
  • http scans
  • http spammer
  • httpsupgrades
  • hunting macro
  • hybrid
  • iana
  • iana id
  • iana ref
  • iana special
  • icedid
  • icmp traffic
  • icons library
  • identifier
  • idlogin sep
  • idnischdr http
  • ieedge chrome1
  • iframe
  • inbound
  • incapsula
  • indicator
  • indicator facts
  • indonesia
  • info
  • info header
  • informative
  • injection
  • installcore
  • installer
  • installpack
  • installs
  • intel
  • intel mac
  • internal
  • international
  • internet
  • ioc
  • iocs
  • ip address
  • ip check
  • ip detections
  • ip related
  • ips collection
  • ip summary
  • ip traffic
  • ipv4
  • ipv4 add
  • ipv6
  • italy
  • italy unknown
  • it consultant
  • january
  • june
  • kb body
  • key algorithm
  • keybase
  • keygen
  • key identifier
  • key info
  • key value
  • kgs0
  • khtml
  • kiannas law
  • kimsuky
  • kit exploit
  • kls0
  • known tor
  • kovter
  • kryptik
  • labs pulses
  • lance mueller
  • lanc type
  • launcher
  • layer
  • learn
  • less see
  • less whois
  • level3
  • life
  • limited
  • link library
  • linux x8664
  • litespeed x
  • llc name
  • llc registry
  • local
  • location united
  • lockbit
  • login yara
  • look
  • lookup wannacry
  • los angeles
  • lowfi
  • low software
  • ltd dba
  • macintosh
  • mailrubar
  • main
  • malicious
  • malicious site
  • maltiverse
  • malware
  • malware beacon
  • malware cve
  • malware dns
  • malware hosting
  • malware site
  • march
  • markmonitor
  • matsnu
  • mcig sep
  • media
  • media center
  • medium
  • memcommit
  • memory
  • memory pattern
  • memory scanning
  • memreserve
  • meta
  • meta http
  • meta name
  • metro
  • mexico
  • million
  • mimikatz
  • miner
  • mini
  • miori hackers
  • mirai
  • mirai type
  • mirai variant
  • mitre
  • mitre att
  • mitre attack
  • model
  • monitoring
  • moved
  • mozilla
  • msie
  • ms windows
  • ms word
  • mtb aug
  • mtb description
  • mtb may
  • mtb sep
  • mtb showing
  • mueller
  • mutex
  • mydoom
  • namecheap
  • namecheap inc
  • name md5
  • name server
  • name servers
  • name tactics
  • nanocore
  • nanocore rat
  • net168
  • net1680000
  • nethandle
  • netname uch
  • netrange
  • nettype direct
  • network
  • network hijacks
  • networm
  • next
  • next associated
  • nextc type
  • Nextray
  • nexus
  • ninite
  • nircmd
  • node
  • node tcp
  • null
  • number
  • nxdomain
  • nymaim
  • observed dns
  • occamy
  • october
  • olet
  • opencandy
  • orgabusephone
  • organization
  • org domains
  • orgid
  • orgtechhandle
  • orgtechref
  • os2 executable
  • os x
  • otx octoseek
  • otx telemetry
  • o url
  • outbreak
  • overlay
  • overview domain
  • overview ip
  • owner exploit
  • owotrus ca
  • packing t1045
  • panda
  • param
  • parent domain
  • parent net168
  • parents
  • passive dns
  • password
  • paste
  • patcher
  • path
  • pattern
  • pattern domains
  • pattern match
  • pattern urls
  • pdb path
  • pe32
  • pe32 executable
  • pe32 installer
  • pe32 linker
  • pegasus
  • pe resource
  • pe section
  • phishing
  • phishing hsbc
  • phishing site
  • phishtank http
  • photography
  • pii
  • piiexposure
  • playgame
  • play ransomware
  • pony
  • porn type
  • port
  • possible
  • powershell
  • pragma
  • precondition
  • presenoker
  • present june
  • privacy
  • privacy admin
  • privacy billing
  • privacy service
  • privacy tech
  • process details
  • program
  • property value
  • proton
  • proxy
  • psexec
  • pt mora
  • pty ltd
  • public url
  • pulse pulses
  • pulses
  • pulses email
  • pulses otx
  • pulse submit
  • pulses url
  • push
  • pyinstaller
  • pykspa
  • python
  • qakbot
  • qbot
  • quasar rat
  • query
  • radamant
  • ransom
  • ransomexx
  • ransomware
  • rce m2
  • read
  • read c
  • realtek sdk
  • record type
  • record value
  • redacted for
  • redirect
  • redline stealer
  • referrer
  • refresh
  • region create
  • region update
  • registrant name
  • registrar
  • registrar abuse
  • registrar url
  • registrar whois
  • registry arin
  • regsetvalueexa
  • related nids
  • related pulses
  • related tags
  • remcos
  • report spam
  • request
  • request id
  • resolutions
  • response final
  • restart
  • reverse dns
  • revil
  • riskware
  • robots content
  • roleselfservice
  • role title
  • rostpay
  • roundup
  • router dsl2750b
  • r processes
  • runescape
  • runner
  • russia
  • sabey type
  • safe site
  • sameorigin
  • sample
  • samplepath
  • samples
  • scan endpoints
  • script
  • script endif
  • script script
  • script urls
  • search
  • search otx
  • sea x
  • secrisk
  • secure
  • secure server
  • seen
  • september
  • server
  • server ca
  • servers
  • service
  • serving ip
  • seznam
  • sha1
  • sha256
  • shell code
  • shell commands
  • show
  • showing
  • show technique
  • siblings
  • sid name
  • simda
  • site
  • size
  • skynet
  • slcc2
  • smoke loader
  • sodinokibi
  • softcnapp
  • sophos sophos
  • source file
  • south korea
  • spammer
  • span
  • span div
  • span svg
  • spawns
  • spf record
  • srjg
  • ssl certificate
  • stack
  • startpage
  • status
  • status code
  • status domain
  • stealer
  • steam
  • stream
  • strike
  • strings
  • subject key
  • subject public
  • submission
  • submitters
  • suite
  • summary
  • suppobox
  • suricata ipv4
  • susp
  • suspicious
  • suspicious path
  • suspicous ip
  • swrort
  • system
  • systweak
  • t1055
  • t1204 user
  • tags none
  • team
  • team phishing
  • technical city
  • technology
  • telecom
  • telegram strong
  • telper
  • threat
  • threat analyzer
  • threat report
  • threat roundup
  • threats
  • tiggre
  • tinba
  • title
  • title style
  • tmobile
  • tofsee
  • tools
  • top destination
  • top source
  • tor exit
  • tor known
  • tour
  • tracker
  • traffic
  • tree
  • trex
  • trojan
  • trojanclicker
  • trojandropper
  • trojan features
  • trojanspy
  • trojanx
  • trust
  • tsara brashears
  • ttl value
  • tulach
  • tulach type
  • twitter
  • type indicator
  • type name
  • typeof
  • types of
  • ucha
  • uid38009
  • uk collection
  • ukraine
  • ul div
  • unis
  • united
  • united kingdom
  • united states
  • university
  • univjos
  • unknown
  • unknown aaaa
  • unknown ns
  • unlocker
  • unruy
  • unsafe
  • update date
  • updater
  • url analysis
  • url http
  • url https
  • urls
  • urlshortner dec
  • urlshortner sep
  • urls http
  • url summary
  • urls url
  • ursnif
  • useragent
  • utc http
  • utc submissions
  • utf8
  • v2 document
  • v3 serial
  • vawtrak
  • verdict
  • verdict cloud
  • verify
  • veryhigh
  • vipre
  • virgin islands
  • virtool
  • virustotal
  • virut
  • wacatac
  • webtoolbar
  • whitelisted
  • whitelisted ip
  • whois file
  • whois lookup
  • whois lookups
  • whois record
  • whois registrar
  • whois sslcert
  • whois whois
  • win16 ne
  • win32
  • win32 dynamic
  • win32mydoom jun
  • win32mydoom sep
  • win32pcmega jan
  • win32 type
  • win32upatre may
  • win64
  • windows
  • windows nt
  • windows startup
  • withheld
  • worm
  • wow64
  • write
  • write c
  • x509v3 key
  • x509v3 subject
  • x86 baddr
  • xamzexpires600
  • xcitium verdict
  • xfbml1
  • xor ddos
  • xorddos
  • xport
  • xrat
  • xtrat
  • x ua
  • yara detections
  • youth
  • zbot
  • zeus
  • zpevdo

MITRE ATT&CK TTPs

  • T1003 - OS Credential Dumping
  • T1016 - System Network Configuration Discovery
  • T1018 - Remote System Discovery
  • T1023 - Shortcut Modification
  • T1027 - Obfuscated Files or Information
  • T1031 - Modify Existing Service
  • T1040 - Network Sniffing
  • T1041 - Exfiltration Over C2 Channel
  • T1045 - Software Packing
  • T1047 - Windows Management Instrumentation
  • T1049 - System Network Connections Discovery
  • T1053 - Scheduled Task/Job
  • T1055 - Process Injection
  • T1056 - Input Capture
  • T1057 - Process Discovery
  • T1059 - Command and Scripting Interpreter
  • T1060 - Registry Run Keys / Startup Folder
  • T1063 - Security Software Discovery
  • T1068 - Exploitation for Privilege Escalation
  • T1071.001 - Web Protocols
  • T1071.004 - DNS
  • T1071 - Application Layer Protocol
  • T1082 - System Information Discovery
  • T1088 - Bypass User Account Control
  • T1089 - Disabling Security Tools
  • T1096 - NTFS File Attributes
  • T1105 - Ingress Tool Transfer
  • T1107 - File Deletion
  • T1110 - Brute Force
  • T1112 - Modify Registry
  • T1113 - Screen Capture
  • T1119 - Automated Collection
  • T1129 - Shared Modules
  • T1132 - Data Encoding
  • T1140 - Deobfuscate/Decode Files or Information
  • T1143 - Hidden Window
  • T1147 - Hidden Users
  • T1158 - Hidden Files and Directories
  • T1176 - Browser Extensions
  • T1204 - User Execution
  • T1428 - Exploit Enterprise Resources
  • T1449 - Exploit SS7 to Redirect Phone Calls/SMS
  • T1480 - Execution Guardrails
  • T1496 - Resource Hijacking
  • T1497 - Virtualization/Sandbox Evasion
  • T1553.002 - Code Signing
  • T1560 - Archive Collected Data
  • T1563 - Remote Service Session Hijacking
  • T1568 - Dynamic Resolution
  • T1574 - Hijack Execution Flow
  • T1583.005 - Botnet
  • T1583 - Acquire Infrastructure
  • T1598 - Phishing for Information
  • TA0003 - Persistence
  • TA0004 - Privilege Escalation
  • TA0005 - Defense Evasion
  • TA0006 - Credential Access
  • TA0007 - Discovery
  • TA0009 - Collection
  • TA0011 - Command and Control
  • TA0034 - Impact
  • TA0040 - Impact

Passive DNS

  • h1926df059d6d6507f6f72b64ee52cf664.ws

Whois Information

NetRange: 64.70.0.0 - 64.70.111.255 CIDR: 64.70.0.0/18, 64.70.96.0/20, 64.70.64.0/19 NetName: CENTURYLINK-LEGACY-SAVVIS-BLK216 NetHandle: NET-64-70-0-0-1 Parent: NET64 (NET-64-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: CenturyLink Communications, LLC (CCL-534) RegDate: 2000-03-31 Updated: 2018-02-22 Ref: https://rdap.arin.net/registry/ip/64.70.0.0 OrgName: CenturyLink Communications, LLC OrgId: CCL-534 Address: 100 CENTURYLINK DR City: Monroe StateProv: LA PostalCode: 71201 Country: US RegDate: 2018-07-12 Updated: 2024-06-17 Comment: USAGE OF IP SPACE MUST COMPLY WITH OUR ACCEPTABLE USE POLICY: Comment: https://www.lumen.com/en-us/about/legal/acceptable-use-policy.html Comment: Comment: Comment: 1. You are permitted to route the Lumen IP prefixes listed via Public BGP to your alternate ISP from the designated ASN. Any other ASN originating the prefix listed is forbidden. Comment: 2. The Lumen IP prefixes listed can be routed via Public BGP to your alternate ISP as long as you remain an active customer with Lumen and continue to route the prefixes over at least one Lumen Internet circuit without significant traffic engineering. Comment: 3. Should your Internet services with Lumen be discontinued, Lumen reserves the right to have your alternate ISP terminate the routing of the Lumen IP prefixes without advanced notification, should you fail to do so. Comment: 4. All IP Addresses assigned or allocated by Lumen to an end-user (customer or ISP) shall be considered non-portable and will be reclaimed by Lumen upon service termination. Comment: 5. Lumen reserves the right to conduct audits to ensure the LOA conditions are being met. Comment: 6. Usage of IP space must comply with our AUP https://www.lumen.com/en-us/about/legal/acceptable-use-policy.html Comment: Comment: Our looking glass is located at: https://lookingglass.centurylink.com/ Comment: Comment: For subpoena or court order please fax 844.254.5800 or refer to our Trust & Safety page: Comment: https://www.lumen.com/en-us/about/legal/trust-center/trust-and-safety.html Comment: Comment: For abuse issues, please email abuse@aup.lumen.com Comment: All abuse reports MUST include: Comment: * src IP Comment: * dest IP (your IP) Comment: * dest port Comment: * Accurate date/timestamp and timezone of activity Comment: * Intensity/frequency (short log extracts) Comment: * Your contact details (phone and email) Comment: Without these we will be unable to identify the correct owner of the IP address at that point in time. Ref: https://rdap.arin.net/registry/entity/CCL-534 OrgTechHandle: QIA-ARIN OrgTechName: Centurylink IP Admin OrgTechPhone: +1-877-886-6515 OrgTechEmail: ipadmin@centurylink.com OrgTechRef: https://rdap.arin.net/registry/entity/QIA-ARIN OrgRoutingHandle: RPKIR-ARIN OrgRoutingName: RPKI-ROA OrgRoutingPhone: +1-877-886-6515 OrgRoutingEmail: rpki-roa@lumen.com OrgRoutingRef: https://rdap.arin.net/registry/entity/RPKIR-ARIN OrgAbuseHandle: CAD54-ARIN OrgAbuseName: Centurylink Abuse Desk OrgAbusePhone: +1-877-886-6515 OrgAbuseEmail: abuse@aup.lumen.com OrgAbuseRef: https://rdap.arin.net/registry/entity/CAD54-ARIN NetRange: 64.70.19.0 - 64.70.19.255 CIDR: 64.70.19.0/24 NetName: SAVV-S235073-7 NetHandle: NET-64-70-19-0-1 Parent: CENTURYLINK-LEGACY-SAVVIS-BLK216 (NET-64-70-0-0-1) NetType: Reallocated OriginAS: Organization: Worldsite.WS (WORLD-119) RegDate: 2008-01-16 Updated: 2008-01-16 Ref: https://rdap.arin.net/registry/ip/64.70.19.0 OrgName: Worldsite.WS OrgId: WORLD-119 Address: 701 Palomer Airport Road City: Carlsbad StateProv: CA PostalCode: 92009 Country: US RegDate: 2006-11-06 Updated: 2011-09-24 Ref: https://rdap.arin.net/registry/entity/WORLD-119 OrgTechHandle: CRA50-ARIN OrgTechName: Randal, Cole OrgTechPhone: +1-760-602-3000 OrgTechEmail: coler@website.ws OrgTechRef: https://rdap.arin.net/registry/entity/CRA50-ARIN OrgAbuseHandle: CRA50-ARIN OrgAbuseName: Randal, Cole OrgAbusePhone: +1-760-602-3000 OrgAbuseEmail: coler@website.ws OrgAbuseRef: https://rdap.arin.net/registry/entity/CRA50-ARIN RTechHandle: WSU6-ARIN RTechName: Support, WS RTechPhone: +1-760-602-3000 RTechEmail: abuse@website.ws RTechRef: https://rdap.arin.net/registry/entity/WSU6-ARIN