65.49.1.48

Classification: Malicious

65.49.1.48 is a malicious IP address. Reported by 12 threat sources, last seen 2026-09-04. Network: AS6939 Hurricane Electric LLC.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • IoT threat β€” Seen attacking IoT devices.
  • Open proxy β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2023-07-04 14:05:34 2026-09-04 09:07:05 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2023-07-04 14:05:25 2026-09-04 09:07:03 malicious-activity
Malicious Host CIArmy 2023-06-30 08:52:17 2026-09-03 20:01:39 attacker malicious-activity
Proxy IPWhois.io 2025-01-15 00:34:03 2026-06-08 17:10:21 anonymization
Mail Spammer Barracuda 2024-09-27 13:10:11 2026-06-08 17:10:21
Port Scanner AbuseIPDB 2024-06-29 13:20:09 2026-06-08 14:58:01 anomalous-activity
SSH Attacker AbuseIPDB 2024-06-30 16:49:09 2026-06-08 12:34:12 malicious-activity
Bruteforce AbuseIPDB 2024-06-30 09:45:49 2026-06-08 12:34:12 malicious-activity
Hacking AbuseIPDB 2024-07-01 04:53:21 2026-06-08 08:30:23 malicious-activity
Malicious Host AbuseIPDB 2024-07-01 12:31:09 2026-06-07 16:03:36 compromised malicious-activity
HTTP Scrapper AbuseIPDB 2024-07-26 09:21:48 2026-06-07 06:38:57 anomalous-activity
HTTP Attacker AbuseIPDB 2024-06-29 15:30:39 2026-06-07 06:38:57 malicious-activity
Phishing AbuseIPDB 2024-07-26 09:21:48 2026-06-01 06:39:34 malicious-activity
Mail Spammer AbuseIPDB 2024-07-23 17:24:44 2026-06-01 06:39:34 malicious-activity
IMAP Attacker AbuseIPDB 2024-07-26 09:21:48 2026-06-01 06:39:34 malicious-activity
Proxy AbuseIPDB 2025-10-09 06:45:01 2026-05-21 05:58:50 anonymization
DNS Compromise AbuseIPDB 2024-10-30 00:00:24 2026-04-12 18:18:00 compromised
SSH Attacker Blocklist.de 2023-07-21 04:26:50 2025-10-28 11:02:26 malicious-activity
Proxy FireHOL 2023-01-01 01:23:00 2025-10-07 10:00:48 anonymization
DDoS Attacker AbuseIPDB 2025-09-29 16:44:37 2025-09-29 16:44:37 malicious-activity
SQL Injection AbuseIPDB 2024-07-01 04:53:21 2025-08-30 04:05:57 malicious-activity
FTP Attacker AbuseIPDB 2024-09-18 20:15:54 2025-07-24 17:20:56 malicious-activity
Known Attacker AbuseIPDB 2024-10-30 00:00:24 2025-07-18 12:07:05 malicious-activity
DDoS attack AbuseIPDB 2024-06-29 15:28:23 2025-06-29 19:25:38 malicious-activity
IoT Attacker AbuseIPDB 2024-07-24 13:06:46 2025-02-11 08:54:37 malicious-activity
VPN AbuseIPDB 2025-01-13 13:52:58 2025-01-13 13:52:58 anonymization
DNS Poisoning AbuseIPDB 2024-10-02 05:28:40 2025-01-11 23:59:41 compromised
Unauthorized scanning of hosts Blocklist.net.ua 2024-12-13 07:14:38 2025-01-05 15:15:02 malicious-activity
HTTP Attacker Blocklist.de 2024-08-10 08:51:49 2024-10-14 10:18:11 malicious-activity
Malicious Host HoneyDB 2023-07-05 00:00:00 2024-04-16 00:00:00 malicious-activity
Anonymizer FireHol 2022-12-29 14:03:07 2022-12-30 01:28:29 anonymization
Anonymizer Maltiverse Research Team 2020-11-21 17:08:06 2021-05-23 00:10:10 anonymizer
Anonymizer Maltiverse 2019-09-20 02:07:39 2019-09-20 02:07:39

Tags

anonymization ssh bruteforce bot anonymizer apache ddos rfi attacker abuse

Whois information

AS name
AS6939 Hurricane Electric LLC
AS registry
arin
AS date
2007-10-04 00:00:00
AS CIDR
65.49.0.0/17
CIDR
65.49.0.0/17
Registrant
Hurricane Electric LLC
Address
760 Mission Court
City
Pleasanton
State
CA
Postal code
94566
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected], [email protected]
First indexed
2019-09-20 02:07:39
Last updated
2026-09-04 09:07:13

Malicious IPs in the same CIDR

65.49.20.12 65.49.20.94 65.49.20.96 65.49.20.97 65.49.1.29 65.49.1.36 65.49.1.40 65.49.1.44 65.49.1.53 65.49.1.52 65.49.1.61 65.49.1.60 65.49.1.77 65.49.1.79 65.49.1.84 65.49.1.85 65.49.1.87 65.49.1.97 65.49.1.98 65.49.20.107 65.49.20.110 65.49.20.114 65.49.20.121 65.49.20.126 65.49.20.83