IP Profile

🖥 127.0.0.1 — Unresolved

127.0.0.0/24 · IP Blocklists · threat 0.50 · 28x · 8 sources

reputation 40.4 (ELEVATED) · first seen Aug 06, 2026 · last seen 4d ago
No special flags ip medium-severity auto-tagged

Reputation

40.4
ELEVATED

Threat Score

0.50
28 sightings

ASN

unresolved

Peers on ASN

0
malicious co-tenants

Bad neighborhood

3
127.0.0.0/24

Country

unresolved

🕵 Team Cymru Scout

Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.

🌐 Network & Geo (local-first)

IP127.0.0.1
Organization
ASN
Netname
Netblock
Reverse DNS (PTR)
Country

Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.

🔥 Threat severity

No local data.

Reporting Sources for this IP (8)

FireHOL: coinbl_hosts.ipsetIP Blocklists
MITRE ATT&CK EnterpriseATT&CK
ThreatView C2 HuntingC2 Attribution
NVD Recent CVEsVulnerabilities
NVD CVE 2.0 APIVulnerabilities
MITRE ATT&CK Groups (STIX)ATT&CK Actors
ThreatView C2 Cobalt StrikeC2 Attribution
MITRE ATT&CK (STIX)Framework

Passive DNS — domains resolving here (50)

27.78.216.130 2026-08-07 16:38:25
167.179.96.140 2026-08-08 10:03:33
144.202.73.210 2026-08-08 10:26:34
213.144.128.40 2026-08-11 06:42:37
149.28.37.137 2026-08-12 03:47:10
149.28.121.179 2026-08-12 04:01:58
27.73.168.239 2026-08-12 17:41:26
27.79.177.199 2026-08-13 19:57:45
27.79.177.213 2026-08-13 20:04:32
27.79.177.166 2026-08-13 20:09:21
27.79.2.33 2026-08-14 04:30:59
27.79.2.39 2026-08-14 04:31:06
27.79.2.68 2026-08-14 04:55:54
27.79.2.21 2026-08-14 05:12:42
awsstatics.com 2026-08-15 16:51:52
185.207.250.9 2026-08-16 15:54:02
45.63.61.100 2026-08-17 22:51:37
27.79.2.88 2026-08-17 23:16:07
45.77.233.244 2026-08-18 15:47:27
178.214.160.4 2026-08-18 22:12:52
27.79.2.42 2026-08-20 18:42:54
141.164.58.134 2026-08-20 19:31:50
155.138.160.136 2026-08-21 08:40:11
136.244.96.75 2026-08-22 00:50:13
27.70.82.89 2026-08-23 03:26:55
108.61.252.155 2026-08-23 13:15:45
45.63.61.189 2026-08-24 01:53:08
45.77.101.158 2026-08-24 04:12:27
209.250.226.207 2026-08-24 15:57:29
137.220.40.196 2026-08-24 16:17:59
207.246.70.66 2026-08-24 17:56:21
45.32.195.225 2026-08-24 22:30:28
140.82.23.44 2026-08-25 01:02:36
64.176.80.51 2026-08-26 00:12:24
45.76.159.214 2026-08-26 04:45:30
45.32.195.109 2026-08-26 05:34:38
107.191.44.214 2026-08-26 06:25:58
baumar.abodcify.com 2026-08-26 07:11:07
45.77.31.200 2026-08-26 16:26:33
207.246.98.23 2026-08-27 15:43:54
45.76.213.110 2026-08-27 15:45:29
45.76.166.209 2026-08-27 15:45:36
45.63.43.188 2026-08-28 19:45:57
104.207.131.9 2026-08-28 23:59:05
140.82.5.101 2026-08-29 12:19:10
139.180.208.56 2026-08-29 12:26:36
65.20.76.129 2026-08-29 12:32:46
140.82.32.54 2026-08-29 12:32:54
45.63.126.205 2026-08-30 20:37:04
140.82.37.98 2026-08-31 06:42:51

🏠 Same /24 — 127.0.0.0/24 (3 other malicious IPs)

Other flagged IPs in the same /24 — a concentration here suggests a compromised or abused block.

IPCategoryFamilyThreat
127.0.0.2 IP Blocklists- dossier
127.0.0.4 IP Blocklists- dossier
127.0.0.9 IP Blocklists- dossier
All in this subnet Bulk takedown

Case & Takedown Links

No cases or takedowns yet.

+ Case Takedown

Enrichments

classification

Stored Enrichment Data Enrich Now

1 enrichment records on file (history preserved).

📁 Case Management

+ New case from this
Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php