104.168.138.157

Classification: Malicious

104.168.138.157 is a malicious IP address. Linked to Emotet malware. Reported by 2 threat sources, last seen 2026-09-04. Network: AS54290 HostPapa.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: EMOTET (S0367)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2022-12-22 14:20:01 2026-09-04 10:28:11 attacker malicious-activity
Emotet Telefonica CO SOC 2019-05-07 13:17:19 2019-05-07 13:17:19 S0367 Emotet T1566 Phishing

Tags

emotet banker compromised payload delivery

Whois information

AS name
AS54290 HostPapa
AS registry
arin
AS date
2014-09-03 00:00:00
AS CIDR
104.168.128.0/17
CIDR
104.168.128.0/17
Registrant
HostPapa
Address
12101 Tukwila International Blvd, 3rd Floor, Suite 320
City
Seattle
State
WA
Postal code
98104
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected]
First indexed
2019-05-07 13:17:19
Last updated
2026-09-04 10:28:11

Malicious IPs in the same CIDR

104.168.234.253 104.168.214.209 104.168.145.83 104.168.134.244 104.168.145.8 104.168.236.91 104.168.169.132 104.168.138.157 104.168.151.116 104.168.151.47 104.168.173.43 104.168.166.234 104.168.159.220 104.168.144.207 104.168.174.32 104.168.170.88