General Information

Submitter Diversity: Low
Risk (0-10)details: 0
RESEARCHER: THIS IP IS USED FOR INTERNET WIDE RESEARCH SCANS
IP Address (click for more detail): 64.62.197.32
Hostname: scan-37a.shadowserver.io
Country:  US
ASN: 6939
AS Name:  HURRICANE - Hurricane Electric LLC, US
Network:  64.62.128.0/17 (64.62.128.0-64.62.255.255) 64.63.0.0
Reports:  - none -
Targets:  - none -
First Reported: N/A
Most Recent Report: N/A
Comment: - none -
Abuse Contact for AS6939: [email protected]
Links to articles about the IP from rosti.bin.re

Note: We update the data once an hour. To refresh the data, click here. Not all source IPs in our database are "attackers". There are a few common false positives. For example, hosts that participate in P2P networks, mail servers, load balancers and DNS servers are some of the most common issues. For details, click on the number of reports. Clicking on the number of reports may allow you to conclude if a report is a false positive or not. Scroll down for information from other data feeds.

SSH/Telnet Logs

Username and Password Details
Total AttemptsUsernames/day Passwords/dayFirst SeenLast Seen
1112021-11-292021-11-29

Web Honeypot Logs

Date Reports Different URLs Different User Agents
2026-09-21812
2026-09-19725
2026-09-181114
2026-06-10665
2026-06-09523
2026-06-0841623
2026-06-0724612
2026-06-0617610
2026-06-0525716
2026-06-04733
2026-06-0316610
2026-06-021257
2026-06-011738
2026-05-3122714

For more details about the web honeypot, see the Weblogs Page. Do not use these reports to identify IP addresses as "bad" for now.

External Threat Feeds

This data was retrieved from various external data feeds.

First Seen Last Seen Feed
2021-12-182026-10-03Port 22 Scanner
2024-08-212026-10-03Port 25 Scanner
2024-06-052026-10-03Port 443 Scanner
2024-06-052026-10-03Port 80 Scanner
2024-06-052026-10-03Apache Web Server Scanner
2024-06-052026-10-03Bruteforce
2021-03-292026-10-03CI Army List
2023-06-082026-10-03Shadowserver
Check Threatstop for more data link arrow