172.64.80.1
Classification: Whitelisted
172.64.80.1 is a whitelisted (trusted) IP address. Reported by 10 threat sources, last seen 2026-09-03. Network: AS13335 Cloudflare, Inc..
Current activity
- Content Delivery Network — Belongs to a CDN with many allocated resources.
- Hosting provider — Shared hosting infrastructure.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154) DCRAT (S9017) CONFICKER (S0608) EMOTET (S0367) ASTAROTH (S0373)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Matched whitelist source: Cloudflare | Maltiverse | 2026-07-17 17:15:57 | 2026-09-03 01:04:21 | benign | |
| Malicious URL | Hybrid-Analysis | 2023-05-29 10:45:04 | 2023-05-29 10:45:04 | ||
| Cobalt Strike | ThreatFox Abuse.ch | 2022-03-12 00:02:07 | 2022-12-28 10:18:26 | malicious-activity | S0154 Cobalt Strike |
| Phishing | Phishtank | 2022-02-15 07:20:05 | 2022-07-13 11:20:07 | compromised malicious-activity | |
| Malicious url | 2022-07-13 02:46:12 | 2022-07-13 02:46:12 | malicious-activity | ||
| Phishing | OpenPhish | 2022-05-14 12:03:01 | 2022-07-13 00:42:59 | compromised malicious-activity | |
| Malware Download | URLhaus Abuse.ch | 2022-02-18 18:15:29 | 2022-07-12 12:15:08 | malicious-activity | |
| Alien | ThreatFox Abuse.ch | 2022-05-16 11:21:17 | 2022-07-11 09:19:16 | malicious-activity | |
| Phishing Steam | Phishtank | 2022-02-18 14:20:08 | 2022-07-11 00:20:11 | compromised malicious-activity | |
| SMSspy | ThreatFox Abuse.ch | 2022-07-09 12:19:15 | 2022-07-09 12:19:15 | malicious-activity | |
| Phishing Bradesco | Phishtank | 2022-04-27 14:20:17 | 2022-07-08 17:20:11 | compromised malicious-activity | |
| Phishing Bank Millennium | Phishtank | 2022-03-14 13:20:17 | 2022-07-07 10:20:12 | compromised malicious-activity | |
| virut | Maltiverse Research Team | 2022-02-22 01:02:42 | 2022-07-07 01:04:30 | malicious-activity | |
| Cobalt Strike | Maltiverse Research Team | 2022-07-05 14:33:46 | 2022-07-05 14:33:46 | S0154 Cobalt Strike | |
| DCRat | ThreatFox Abuse.ch | 2022-07-05 00:01:15 | 2022-07-05 00:01:15 | malicious-activity | S9017 DCRAT |
| Phishing Allegro | Phishtank | 2022-02-14 07:20:06 | 2022-07-03 02:20:27 | compromised malicious-activity | |
| Phishing ABSA Bank | Phishtank | 2022-02-19 13:20:06 | 2022-06-24 00:20:18 | compromised malicious-activity | |
| conficker | Maltiverse Research Team | 2022-06-16 00:26:50 | 2022-06-16 00:26:50 | malicious-activity | S0608 Conficker |
| Loki Password Stealer (PWS) | ThreatFox Abuse.ch | 2022-03-19 00:08:46 | 2022-06-09 00:04:22 | malicious-activity | |
| Phishing East Japan Railway Company | Phishtank | 2022-06-07 03:20:07 | 2022-06-07 03:20:07 | compromised malicious-activity | |
| Emotet | ThreatFox Abuse.ch | 2022-05-26 08:18:49 | 2022-05-26 08:18:49 | malicious-activity | S0367 Emotet |
| Malware distribution site | Malwaremustdie.org | 2022-05-26 04:02:21 | 2022-05-26 04:02:21 | malicious-activity | |
| Phishing Caixa | Phishtank | 2022-04-28 00:59:55 | 2022-05-20 05:20:28 | compromised malicious-activity | |
| Phishing Raiffeisen Bank | Phishtank | 2022-05-17 14:20:34 | 2022-05-17 14:20:34 | compromised malicious-activity | |
| Phishing Facebook | Phishtank | 2022-03-17 03:20:06 | 2022-05-16 00:39:11 | compromised malicious-activity | |
| Phishing | Maltiverse | 2022-02-13 12:41:54 | 2022-05-14 00:42:59 | compromised | |
| Phishing Internal Revenue Service | Phishtank | 2022-02-15 01:20:20 | 2022-05-12 21:20:09 | compromised malicious-activity | |
| Social Engineering | Maltiverse | 2022-02-13 12:43:49 | 2022-05-08 12:42:55 | malicious-activity | |
| Social Engineering | Phishtank | 2022-02-22 22:20:41 | 2022-05-05 14:23:43 | malicious-activity | |
| Unwanted Software | URLhaus Abuse.ch | 2022-05-05 13:15:18 | 2022-05-05 13:15:33 | malicious-activity | |
| Phishing AEON Card | Phishtank | 2022-04-28 19:20:07 | 2022-04-28 19:20:10 | compromised malicious-activity | |
| Facebook phishing | Antiphishing.com.ar | 2022-04-24 04:12:54 | 2022-04-24 04:12:54 | ||
| Газпромбанк phishing | Antiphishing.com.ar | 2022-04-08 01:32:05 | 2022-04-08 01:32:05 | ||
| microsoft phishing | Antiphishing.com.ar | 2022-04-08 01:32:00 | 2022-04-08 01:32:00 | ||
| Malware | URLhaus Abuse.ch | 2022-03-19 06:16:19 | 2022-03-28 05:15:33 | malicious-activity | |
| Phishing Bendigo Bank | Phishtank | 2022-03-28 00:20:06 | 2022-03-28 00:20:06 | compromised malicious-activity | |
| Social Engineering | URLhaus Abuse.ch | 2022-03-19 06:16:19 | 2022-03-24 08:15:30 | malicious-activity | |
| ING Groep phishing | Antiphishing.com.ar | 2022-03-11 01:52:13 | 2022-03-11 01:52:13 | ||
| Social Engineering | Antiphishing.com.ar | 2022-03-11 01:52:13 | 2022-03-11 01:52:13 | malicious-activity | |
| Phishing Itau | Phishtank | 2022-02-22 22:20:41 | 2022-02-22 22:20:41 | compromised malicious-activity | |
| Astaroth | ThreatFox Abuse.ch | 2022-02-22 00:01:58 | 2022-02-22 00:01:58 | malicious-activity | S0373 Astaroth |
| Phishing Bank of America Corporation | Phishtank | 2022-02-18 18:20:05 | 2022-02-18 18:20:05 | compromised malicious-activity | |
| generic scam phishing | Antiphishing.com.ar | 2022-02-18 01:04:43 | 2022-02-18 01:05:06 | ||
| Instagram phishing | Antiphishing.com.ar | 2022-02-18 01:02:48 | 2022-02-18 01:02:48 | ||
| Phishing Microsoft | Phishtank | 2022-02-13 21:20:07 | 2022-02-15 15:20:05 | compromised malicious-activity |
Tags
cobaltstrike huawei clouds agentemis beacon cobeacon phishing twitter https://twitter.com/h2jazi/status/1546501374350868481 malware_download alien apk alienbot iran malware spyware c&c c2 dga cobalt strike alibaba-cn-net alibaba us technology co. ltd. dcrat darkcrystal rat cloudflarenet as-choopa multa-asn1 loki burkina lokibot lokipws netsec-hk netsec limited clouddata-networks-1 emotet geodo heodo webzilla level-net level-msk ltd. ponynet asbaxetn website-hosting oneprovider-as brainstorm network inc bra geo guildmaWhois information
- AS name
- AS13335 Cloudflare, Inc.
- AS registry
- arin
- AS date
- 2015-02-25 00:00:00
- AS CIDR
- 172.64.80.0/20
- CIDR
- 172.64.0.0/13
- Registrant
- Cloudflare, Inc.
- Address
- 101 Townsend Street
- City
- San Francisco
- State
- CA
- Postal code
- 94102
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected]
- First indexed
- 2022-02-13 12:41:54
- Last updated
- 2026-09-03 01:04:21