IOC Radar
IPHighVerifiedSignal 53/100

64.91.231.91

Location
United StatesUnited States
Lansing, Michigan
ASN
AS32244
SourceDNS
First Seen
Nov 1, 2024
Last Seen
Jan 26, 2026
Nov 1
First Seen
600d ago
Jan 26
Last Seen
148d ago
5
Reports
source reports
53%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
53%
Signal Score
53 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

15 techniques

Network Information

CountryUSUnited States
RegionLansing, Michigan
ASNAS32244
OrganizationSourceDNS

Feed Intelligence Summary

5 reports53% confidence
5
Source reports
53%
Confidence score
Category tags
active scanningcredential harvestingdata exfiltrationhackingindicatormalicious softwaremalwarenetworknorth americaphishingphishing attackprocess injectionreconnaissanceresearchedscannersocial engineeringsubject: ekstret1055t1071.001t1078t1189t1204.002t1486t1565t1566t1566.001t1566.002t1566.003t1566.004t1595.001t1595.002t1595.003united states

Activity Timeline

1 total obs
Jan 26Jan 26

Threat Activity Heatmap

· Peak: 2026-01-26
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
53
SIGNAL
Signal Score
53%
Confidence
5
Reports
First seenNov 1, 2024
Last seenJan 26, 2026
Verified IOC
GeolocationUS
CountryUnited States
LocationLansing, Michigan
ASNAS32244
OrgSourceDNS
Coords42.6898, -84.6427

VirusTotal

Not checked

WHOIS

raw
NetRange: 64.91.224.0 - 64.91.255.255 CIDR: 64.91.224.0/19 NetName: LIQUIDWEB NetHandle: NET-64-91-224-0-1 Parent: NET64 (NET-64-0-0-0-0) NetType: Direct Allocation OriginAS: AS32244 Organization: Liquid Web, L.L.C (LQWB) RegDate: 2001-07-20 Updated: 2012-02-24 Ref: https://rdap.arin.net/registry/ip/64.91.224.0 OrgName: Liquid Web, L.L.C OrgId: LQWB Address: 4210 Creyts Rd. City: Lansing StateProv: MI PostalCode: 48917 Country: US RegDate: 2001-07-20 Updated: 2020-04-29 Ref: https://rdap.arin.net/registry/entity/LQWB ReferralServer: rwhois://rwhois.liquidweb.com:4321 OrgAbuseHandle: ABUSE551-ARIN OrgAbuseName: Abuse OrgAbusePhone: +1-800-580-4985 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE551-ARIN OrgTechHandle: IPADM47-ARIN OrgTechName: IP Administrator OrgTechPhone: +1-800-580-4985 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN RAbuseHandle: IPADM47-ARIN RAbuseName: IP Administrator RAbusePhone: +1-800-580-4985 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN RTechHandle: IPADM47-ARIN RTechName: IP Administrator RTechPhone: +1-800-580-4985 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 4 months ago
Appeared in 5 threat reports