AbuseIPDB » 172.67.212.68
172.67.212.68 was found in our database!
This IP was reported 2 times. Confidence of
Abuse
is 0% : ?
ISP
Cloudflare, Inc.
Usage Type
Content Delivery Network
ASN
AS13335
Domain Name
cloudflare.com
Country
๐บ๐ธ
United States of America
City
San Francisco, California
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
Important Note: 172.67.212.68 is an IP address from within
our whitelist belonging to the subnet
172.64.0.0/13 ,
which we identify as: "Cloudflare Reverse Proxy" .
Whitelisted netblocks are typically owned by trusted entities, such as Google
or Microsoft who may use them for search engine spiders. However, these same entities
sometimes also provide cloud servers and mail services which are easily abused. Pay special
attention when trusting or distrusting these IPs.
IP Abuse Reports for 172.67.212.68 :
This IP address has been reported a total of
2
times from
2 distinct
sources.
172.67.212.68 was first reported on
June 26th 2024 , and the most recent report was
2 months ago .
Old Reports:
The most recent abuse report for this IP address is from
2 months ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ป๐ณ
T4k3d0wnprocess_webprotect
2026-05-20 00:40:00
(2 months ago)
Target Domain: xeno.now (hxxps://xeno.now)
Proxy/Infrastructure Provider: Cloudflare Inc.
Anycast ...
show more
Target Domain: xeno.now (hxxps://xeno.now)
Proxy/Infrastructure Provider: Cloudflare Inc.
Anycast Edge IPs: 104.21.16.88 | 172.67.212.68
JARM Fingerprint: fd9575eb422b9da33829df00a0c0ea7cfd2da9754410811d8ab96efd0b05906a (Standard Cloudflare Edge TLS)
1. ACTIVE SUBDOMAINS & ROUTING DIAGRAM
- xeno.now (Main C2 / Phishing Delivery Platform)
- www.xeno.now (Backup Routing Record)
- status.xeno.now (C2 Activity Monitor / Direct Beaconing Traffic Node)
- *.xeno.now (Wildcard Configured for Dynamic Payload Routing Bypass)
2. CRYPTOGRAPHIC & TIMELINE EVIDENCE
- Certificate Transparency (CT) Logs verified active as of March 2026.
- Authority Issuance Chain: Alternating between Google Trust Services (CN=WE1, CN=WR1) and Let's Encrypt (CN=R13).
- Campaign Timeline: Earliest certificate footprint recorded on March 31, 2026. Ongoing automated rotation detected.
- Threat Context: Subdomains explicitly utilized to proxy and obfuscate backend Command & Control (C2) server origins.
show less
Spoofing
Bad Web Bot
Exploited Host
Web App Attack
Phishing
Hacking
SQL Injection
Anonymous
2024-06-26 12:56:00
(2 years ago)
Fake health news scamvertising
From: 11Ibs Per Week! <[email protected] >
Subj ...
show more
Fake health news scamvertising
From: 11Ibs Per Week! <[email protected] >
Subject: Outperforming Ozempic? Drop 11 Ibs in Just One Week!
Received: from 157.15.203.20 (EHLO b3d48b7d43.talkinggreeting.com) - WEBYNE DATA CENTRE PRIVATE LIMITED - BLACKLISTED
Header Reply-To: [email protected] = ditto
Message URL:
- duo.velvetchairsalon.com = 43.231.127.148 Everdata Technologies Pvt Ltd
- mwebresearch.com = 104.21.7.83, 172.67.135.230 Cloudflare
- goserolean.com = 104.21.45.84, 172.67.212.68 Cloudflare
- serolean.com = 104.21.52.115, 172.67.198.125 Cloudflare - "call 877-276-9717"
- buygoods.com = 172.66.43.115, 172.66.40.141 Cloudflare
Ref unknown entity apartment - 18711 Sherman Way #106E Reseda, CA 91335
Ref BuyGoods 1201 N Orange St Ste 7223, Wilmington DE 19801
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Bad Web Bot
Showing 1 to
2
of 2 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: