64.98.148.139 Threat Intelligence and Host Information
ipinfopage
General
This page contains threat intelligence information for the IPv4 address
64.98.148.139 and was generated either as a result of
observed malicious activity or as an information gathering exercise to assist with
enrichment of security events and context. All information is gathered passively
through aggregation of public sources, or observations through activity upon honeynets.
The host score is calculated through a series of statistically weighted values and
machine learning which takes into account metadata such as host information, frequency,
volume and global distribution of malicious activity, association with other known
malicious hosts or networks, proxying or anonymising behaviour such as with tor exit
nodes, residential proxies or VPN services, and many other attributes. These values are
historical and indicative only - and should not be taken to be an accurate representation
of the users, businesses or networks in which they reside.
🟡 Low Risk —
29/100
Geographic Location
Host and Network Information
- View other sources:
Spamhaus
VirusTotal
Shodan
AbuseIPDB
- Country: Canada
- Noticed: 1 time
- Protocols Attacked: SSH
- Countries Attacked: Germany, India, Italy, Japan, Netherlands, Philippines, Taiwan, United States of America
- Open Ports: 53
- Tor Node: No
- aaaa
- accept
- address
- address domain
- admin
- a domains
- age86400 set
- alerts
- all scoreblue
- all search
- america asn
- analysis date
- as1221
- as16625 akamai
- as20940
- as21928
- as25825
- as32133
- as4230 claro
- as44273 host
- as701 verizon
- as9318 sk
- ascii text
- asnone united
- av detections
- backdoor
- body
- canada unknown
- certificate
- chrome
- cname
- contacted
- cookie
- copy
- creation date
- crlf line
- database
- date
- domain
- domains
- downloader
- email please
- emails
- english
- entries
- expiration date
- fedora
- filehash
- files
- files ip
- files location
- files related
- flag united
- for privacy
- Generic36.ABKD
- gmt content
- gmt etag
- gmt max
- gmt path
- hostname
- ids detections
- installer
- intel
- ipv4
- location canada
- loveland
- malware
- maxage apt
- maxsize apt
- meta
- minage apt
- mirai
- moved
- msie
- ms windows
- name servers
- new pulse
- next
- nginx http
- ns nxdomain
- number
- nxdomain
- open ports
- otx scoreblue
- overview ip
- passive dns
- path max
- pe32
- pulse pulses
- pulse submit
- rdds service
- record
- record value
- redacted for
- registrant
- registrar
- related nids
- reverse dns
- sabey
- scan endpoints
- script domains
- script urls
- search
- server
- servers
- set cookie
- show
- showing
- south korea
- status
- taiwan as3462
- tech contact
- template
- title
- trojan
- trojanproxy
- tue jun
- type
- united
- united states
- unknown
- url analysis
- urls
- users
- verdict
- virtool
- west domains
- write
- yara detections
MITRE ATT&CK TTPs
- T1003 - OS Credential Dumping
Passive DNS
Attack Log References
Whois Information
NetRange: 64.98.0.0 - 64.99.255.255
CIDR: 64.98.0.0/15
NetName: TUCOWS-BLK2
NetHandle: NET-64-98-0-0-1
Parent: NET64 (NET-64-0-0-0-0)
NetType: Direct Allocation
OriginAS:
Organization: Tucows.com Co. (TUCOW)
RegDate: 2000-05-18
Updated: 2022-02-11
Comment: Geofeed https://geoip.tingfiber.net/tf-geofeed.csv
Ref: https://rdap.arin.net/registry/ip/64.98.0.0
OrgName: Tucows.com Co.
OrgId: TUCOW
Address: 96 Mowat Avenue
City: Toronto
StateProv: ON
PostalCode: M6K-3M1
Country: CA
RegDate: 2006-02-07
Updated: 2024-10-31
Ref: https://rdap.arin.net/registry/entity/TUCOW
OrgNOCHandle: NOC12422-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-416-535-0123
OrgNOCEmail: arin-noc@tucows.com
OrgNOCRef: https://rdap.arin.net/registry/entity/NOC12422-ARIN
OrgAbuseHandle: AST147-ARIN
OrgAbuseName: Abuse Security Team
OrgAbusePhone: +1-416-535-0123
OrgAbuseEmail: arin-abuse@tucows.com
OrgAbuseRef: https://rdap.arin.net/registry/entity/AST147-ARIN
OrgTechHandle: DIACO-ARIN
OrgTechName: Diaconita, Dragos
OrgTechPhone: +1-416-535-0123
OrgTechEmail: ddiaconita@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/DIACO-ARIN
OrgTechHandle: FJO19-ARIN
OrgTechName: Obispo, Francisco Jose
OrgTechPhone: +1-949-706-2300
OrgTechEmail: francisco@unr.com
OrgTechRef: https://rdap.arin.net/registry/entity/FJO19-ARIN
OrgTechHandle: LEEKE55-ARIN
OrgTechName: Lee, Kevin
OrgTechPhone: +1-416-535-0123
OrgTechEmail: klee@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/LEEKE55-ARIN
OrgTechHandle: SCURT4-ARIN
OrgTechName: Scurt, Matei
OrgTechPhone: +1-919-753-4126
OrgTechEmail: mscurt@ting.com
OrgTechRef: https://rdap.arin.net/registry/entity/SCURT4-ARIN
OrgTechHandle: OPERA26-ARIN
OrgTechName: Operations Team
OrgTechPhone: +1-416-535-0123
OrgTechEmail: dnstech@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/OPERA26-ARIN
OrgTechHandle: LEVYR7-ARIN
OrgTechName: Levy, Reg
OrgTechPhone: +1-323-880-0831
OrgTechEmail: rlevy@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/LEVYR7-ARIN
OrgTechHandle: ZAMBR10-ARIN
OrgTechName: Zambrano, Manuel
OrgTechPhone: +1-949-706-2300
OrgTechEmail: mzambrano@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/ZAMBR10-ARIN
OrgTechHandle: NOC2038-ARIN
OrgTechName: Network Operations Center
OrgTechPhone: +1-416-531-5584
OrgTechEmail: arin-maint@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/NOC2038-ARIN
OrgTechHandle: HALAS9-ARIN
OrgTechName: Halassy-Creamer, Joshua
OrgTechPhone: +1-416-535-0123
OrgTechEmail: jhalassycreamer@tucowsinc.com
OrgTechRef: https://rdap.arin.net/registry/entity/HALAS9-ARIN
RAbuseHandle: AST147-ARIN
RAbuseName: Abuse Security Team
RAbusePhone: +1-416-535-0123
RAbuseEmail: arin-abuse@tucows.com
RAbuseRef: https://rdap.arin.net/registry/entity/AST147-ARIN
RTechHandle: DIACO-ARIN
RTechName: Diaconita, Dragos
RTechPhone: +1-416-535-0123
RTechEmail: ddiaconita@tucows.com
RTechRef: https://rdap.arin.net/registry/entity/DIACO-ARIN
RNOCHandle: NOC12422-ARIN
RNOCName: Network Operations Center
RNOCPhone: +1-416-535-0123
RNOCEmail: arin-noc@tucows.com
RNOCRef: https://rdap.arin.net/registry/entity/NOC12422-ARIN
RTechHandle: OPERA26-ARIN
RTechName: Operations Team
RTechPhone: +1-416-535-0123
RTechEmail: dnstech@tucows.com
RTechRef: https://rdap.arin.net/registry/entity/OPERA26-ARIN
NetRange: 64.98.144.0 - 64.98.159.255
CIDR: 64.98.144.0/20
NetName: TF-CNCO02-BLK01
NetHandle: NET-64-98-144-0-1
Parent: TUCOWS-BLK2 (NET-64-98-0-0-1)
NetType: Reallocated
OriginAS:
Organization: Ting Fiber Inc. (TF-178)
RegDate: 2024-10-30
Updated: 2024-10-30
Ref: https://rdap.arin.net/registry/ip/64.98.144.0
OrgName: Ting Fiber Inc.
OrgId: TF-178
Address: 800D Louisville Street
City: Starkville
StateProv: MS
PostalCode: 39759
Country: US
RegDate: 2015-04-13
Updated: 2024-12-13
Ref: https://rdap.arin.net/registry/entity/TF-178
OrgAbuseHandle: AST150-ARIN
OrgAbuseName: Abuse Security Team
OrgAbusePhone: +1-888-511-7284
OrgAbuseEmail: abuse@ting.com
OrgAbuseRef: https://rdap.arin.net/registry/entity/AST150-ARIN
OrgTechHandle: DIACO-ARIN
OrgTechName: Diaconita, Dragos
OrgTechPhone: +1-416-535-0123
OrgTechEmail: ddiaconita@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/DIACO-ARIN
OrgTechHandle: OPERA515-ARIN
OrgTechName: Operations Admin
OrgTechPhone: +1-888-511-7284
OrgTechEmail: dnsadmin@ting.com
OrgTechRef: https://rdap.arin.net/registry/entity/OPERA515-ARIN
OrgTechHandle: LEVYR7-ARIN
OrgTechName: Levy, Reg
OrgTechPhone: +1-323-880-0831
OrgTechEmail: rlevy@tucows.com
OrgTechRef: https://rdap.arin.net/registry/entity/LEVYR7-ARIN
OrgTechHandle: SCURT4-ARIN
OrgTechName: Scurt, Matei
OrgTechPhone: +1-919-753-4126
OrgTechEmail: mscurt@ting.com
OrgTechRef: https://rdap.arin.net/registry/entity/SCURT4-ARIN
OrgTechHandle: MELEC-ARIN
OrgTechName: Mele, Christopher
OrgTechPhone: +1-416-535-0123
OrgTechEmail: cmele@ting.com
OrgTechRef: https://rdap.arin.net/registry/entity/MELEC-ARIN