IPHighVerifiedSignal 53/100
64.91.231.91
Location
Lansing, Michigan
ASN
AS32244
SourceDNS
First Seen
Nov 1, 2024
Last Seen
Jan 26, 2026
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
53%
Signal Score
53 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionLansing, Michigan
ASNAS32244
OrganizationSourceDNS
Feed Intelligence Summary
5 reports53% confidence
5
Source reports
53%
Confidence score
Category tags
active scanningcredential harvestingdata exfiltrationhackingindicatormalicious softwaremalwarenetworknorth americaphishingphishing attackprocess injectionreconnaissanceresearchedscannersocial engineeringsubject: ekstret1055t1071.001t1078t1189t1204.002t1486t1565t1566t1566.001t1566.002t1566.003t1566.004t1595.001t1595.002t1595.003united states
Activity Timeline
Jan 26Jan 26
Threat Activity Heatmap
· Peak: 2026-01-26LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
53
SIGNAL
Signal Score
53%
Confidence
5
Reports
First seenNov 1, 2024
Last seenJan 26, 2026
Verified IOC
GeolocationUS
CountryUnited States
LocationLansing, Michigan
ASNAS32244
OrgSourceDNS
Coords42.6898, -84.6427
VirusTotal
Not checked
WHOIS
- raw
- NetRange: 64.91.224.0 - 64.91.255.255 CIDR: 64.91.224.0/19 NetName: LIQUIDWEB NetHandle: NET-64-91-224-0-1 Parent: NET64 (NET-64-0-0-0-0) NetType: Direct Allocation OriginAS: AS32244 Organization: Liquid Web, L.L.C (LQWB) RegDate: 2001-07-20 Updated: 2012-02-24 Ref: https://rdap.arin.net/registry/ip/64.91.224.0 OrgName: Liquid Web, L.L.C OrgId: LQWB Address: 4210 Creyts Rd. City: Lansing StateProv: MI PostalCode: 48917 Country: US RegDate: 2001-07-20 Updated: 2020-04-29 Ref: https://rdap.arin.net/registry/entity/LQWB ReferralServer: rwhois://rwhois.liquidweb.com:4321 OrgAbuseHandle: ABUSE551-ARIN OrgAbuseName: Abuse OrgAbusePhone: +1-800-580-4985 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE551-ARIN OrgTechHandle: IPADM47-ARIN OrgTechName: IP Administrator OrgTechPhone: +1-800-580-4985 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN RAbuseHandle: IPADM47-ARIN RAbuseName: IP Administrator RAbusePhone: +1-800-580-4985 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN RTechHandle: IPADM47-ARIN RTechName: IP Administrator RTechPhone: +1-800-580-4985 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/IPADM47-ARIN
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 1 year ago · Last seen 4 months ago
Appeared in 5 threat reports