172.64.80.1

Classification: Whitelisted

172.64.80.1 is a whitelisted (trusted) IP address. Reported by 10 threat sources, last seen 2026-09-03. Network: AS13335 Cloudflare, Inc..

Current activity

  • Content Delivery Network — Belongs to a CDN with many allocated resources.
  • Hosting provider — Shared hosting infrastructure.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154) DCRAT (S9017) CONFICKER (S0608) EMOTET (S0367) ASTAROTH (S0373)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Matched whitelist source: Cloudflare Maltiverse 2026-07-17 17:15:57 2026-09-03 01:04:21 benign
Malicious URL Hybrid-Analysis 2023-05-29 10:45:04 2023-05-29 10:45:04
Cobalt Strike ThreatFox Abuse.ch 2022-03-12 00:02:07 2022-12-28 10:18:26 malicious-activity S0154 Cobalt Strike
Phishing Phishtank 2022-02-15 07:20:05 2022-07-13 11:20:07 compromised malicious-activity
Malicious url Twitter 2022-07-13 02:46:12 2022-07-13 02:46:12 malicious-activity
Phishing OpenPhish 2022-05-14 12:03:01 2022-07-13 00:42:59 compromised malicious-activity
Malware Download URLhaus Abuse.ch 2022-02-18 18:15:29 2022-07-12 12:15:08 malicious-activity
Alien ThreatFox Abuse.ch 2022-05-16 11:21:17 2022-07-11 09:19:16 malicious-activity
Phishing Steam Phishtank 2022-02-18 14:20:08 2022-07-11 00:20:11 compromised malicious-activity
SMSspy ThreatFox Abuse.ch 2022-07-09 12:19:15 2022-07-09 12:19:15 malicious-activity
Phishing Bradesco Phishtank 2022-04-27 14:20:17 2022-07-08 17:20:11 compromised malicious-activity
Phishing Bank Millennium Phishtank 2022-03-14 13:20:17 2022-07-07 10:20:12 compromised malicious-activity
virut Maltiverse Research Team 2022-02-22 01:02:42 2022-07-07 01:04:30 malicious-activity
Cobalt Strike Maltiverse Research Team 2022-07-05 14:33:46 2022-07-05 14:33:46 S0154 Cobalt Strike
DCRat ThreatFox Abuse.ch 2022-07-05 00:01:15 2022-07-05 00:01:15 malicious-activity S9017 DCRAT
Phishing Allegro Phishtank 2022-02-14 07:20:06 2022-07-03 02:20:27 compromised malicious-activity
Phishing ABSA Bank Phishtank 2022-02-19 13:20:06 2022-06-24 00:20:18 compromised malicious-activity
conficker Maltiverse Research Team 2022-06-16 00:26:50 2022-06-16 00:26:50 malicious-activity S0608 Conficker
Loki Password Stealer (PWS) ThreatFox Abuse.ch 2022-03-19 00:08:46 2022-06-09 00:04:22 malicious-activity
Phishing East Japan Railway Company Phishtank 2022-06-07 03:20:07 2022-06-07 03:20:07 compromised malicious-activity
Emotet ThreatFox Abuse.ch 2022-05-26 08:18:49 2022-05-26 08:18:49 malicious-activity S0367 Emotet
Malware distribution site Malwaremustdie.org 2022-05-26 04:02:21 2022-05-26 04:02:21 malicious-activity
Phishing Caixa Phishtank 2022-04-28 00:59:55 2022-05-20 05:20:28 compromised malicious-activity
Phishing Raiffeisen Bank Phishtank 2022-05-17 14:20:34 2022-05-17 14:20:34 compromised malicious-activity
Phishing Facebook Phishtank 2022-03-17 03:20:06 2022-05-16 00:39:11 compromised malicious-activity
Phishing Maltiverse 2022-02-13 12:41:54 2022-05-14 00:42:59 compromised
Phishing Internal Revenue Service Phishtank 2022-02-15 01:20:20 2022-05-12 21:20:09 compromised malicious-activity
Social Engineering Maltiverse 2022-02-13 12:43:49 2022-05-08 12:42:55 malicious-activity
Social Engineering Phishtank 2022-02-22 22:20:41 2022-05-05 14:23:43 malicious-activity
Unwanted Software URLhaus Abuse.ch 2022-05-05 13:15:18 2022-05-05 13:15:33 malicious-activity
Phishing AEON Card Phishtank 2022-04-28 19:20:07 2022-04-28 19:20:10 compromised malicious-activity
Facebook phishing Antiphishing.com.ar 2022-04-24 04:12:54 2022-04-24 04:12:54
Газпромбанк phishing Antiphishing.com.ar 2022-04-08 01:32:05 2022-04-08 01:32:05
microsoft phishing Antiphishing.com.ar 2022-04-08 01:32:00 2022-04-08 01:32:00
Malware URLhaus Abuse.ch 2022-03-19 06:16:19 2022-03-28 05:15:33 malicious-activity
Phishing Bendigo Bank Phishtank 2022-03-28 00:20:06 2022-03-28 00:20:06 compromised malicious-activity
Social Engineering URLhaus Abuse.ch 2022-03-19 06:16:19 2022-03-24 08:15:30 malicious-activity
ING Groep phishing Antiphishing.com.ar 2022-03-11 01:52:13 2022-03-11 01:52:13
Social Engineering Antiphishing.com.ar 2022-03-11 01:52:13 2022-03-11 01:52:13 malicious-activity
Phishing Itau Phishtank 2022-02-22 22:20:41 2022-02-22 22:20:41 compromised malicious-activity
Astaroth ThreatFox Abuse.ch 2022-02-22 00:01:58 2022-02-22 00:01:58 malicious-activity S0373 Astaroth
Phishing Bank of America Corporation Phishtank 2022-02-18 18:20:05 2022-02-18 18:20:05 compromised malicious-activity
generic scam phishing Antiphishing.com.ar 2022-02-18 01:04:43 2022-02-18 01:05:06
Instagram phishing Antiphishing.com.ar 2022-02-18 01:02:48 2022-02-18 01:02:48
Phishing Microsoft Phishtank 2022-02-13 21:20:07 2022-02-15 15:20:05 compromised malicious-activity

Tags

cobaltstrike huawei clouds agentemis beacon cobeacon phishing twitter https://twitter.com/h2jazi/status/1546501374350868481 malware_download alien apk alienbot iran malware spyware c&c c2 dga cobalt strike alibaba-cn-net alibaba us technology co. ltd. dcrat darkcrystal rat cloudflarenet as-choopa multa-asn1 loki burkina lokibot lokipws netsec-hk netsec limited clouddata-networks-1 emotet geodo heodo webzilla level-net level-msk ltd. ponynet asbaxetn website-hosting oneprovider-as brainstorm network inc bra geo guildma

Whois information

AS name
AS13335 Cloudflare, Inc.
AS registry
arin
AS date
2015-02-25 00:00:00
AS CIDR
172.64.80.0/20
CIDR
172.64.0.0/13
Registrant
Cloudflare, Inc.
Address
101 Townsend Street
City
San Francisco
State
CA
Postal code
94102
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected], [email protected]
First indexed
2022-02-13 12:41:54
Last updated
2026-09-03 01:04:21