12.139.38.4
Classification: Malicious
12.139.38.4 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-12. Network: AS7018 AT&T Enterprises, LLC.
Current activity
- Known attacker β Seen launching attacks over the Internet.
- Known scanner β Seen scanning hosts over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SSH Attacker | Blocklist.de | 2022-07-20 02:06:50 | 2026-09-12 14:00:55 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2025-04-15 22:03:37 | 2026-09-07 04:31:44 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2025-02-08 22:13:26 | 2026-09-06 19:50:29 | anomalous-activity attacker malicious-activity reconnaissance | |
| SSH Attacker | AbuseIPDB | 2025-04-15 22:03:37 | 2026-09-06 19:50:29 | attacker malicious-activity | |
| SSH Attacker | Blocklist.net.ua | 2025-04-17 16:03:37 | 2026-09-05 16:01:58 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2024-11-18 20:55:35 | 2026-09-04 20:10:18 | attacker compromised malicious-activity | |
| Hacking | AbuseIPDB | 2025-04-17 10:16:04 | 2026-09-03 06:08:58 | attacker malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-09-02 12:33:24 | 2026-09-02 12:33:24 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-09-02 12:33:24 | 2026-09-02 12:33:24 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-04-17 10:16:04 | 2026-09-02 12:33:24 | anomalous-activity attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-06-15 05:07:22 | 2026-09-02 12:33:24 | attacker malicious-activity | |
| FTP Attacker | Blocklist.de | 2026-06-15 10:00:06 | 2026-06-15 10:00:06 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-06-14 14:50:16 | 2026-06-14 14:50:16 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-11-17 01:48:17 | 2026-06-07 19:33:56 | anomalous-activity | |
| Bruteforce | Maltiverse | 2022-10-01 17:53:25 | 2022-12-27 13:54:28 | malicious-activity | |
| Port Scanner | Maltiverse | 2022-10-29 02:24:42 | 2022-12-27 13:25:16 | anomalous-activity | |
| SSH Attacker | Maltiverse | 2022-10-01 17:53:25 | 2022-12-27 13:25:16 | malicious-activity | |
| Hacking | Maltiverse | 2022-10-01 17:53:25 | 2022-10-01 17:53:25 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2022-05-22 03:15:03 | 2022-07-27 03:38:52 | malicious-activity |
Tags
ssh bruteforce bot abuse attacker ftpWhois information
- AS name
- AS7018 AT&T Enterprises, LLC
- AS registry
- arin
- AS date
- 1983-08-23 00:00:00
- AS CIDR
- 12.128.0.0/9
- CIDR
- 12.0.0.0/8
- Registrant
- AT&T Enterprises, LLC
- Address
- 200 S. Laurel AVE.
- City
- Los Angeles
- State
- CA
- Postal code
- 90012
- Country
- US β United States πΊπΈ
- Contact email
- [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2022-05-22 03:15:03
- Last updated
- 2026-09-12 14:00:55
Malicious IPs in the same CIDR
12.156.67.18 12.202.180.216 12.139.38.4 12.218.209.130 12.154.48.194 12.203.54.178 12.131.14.114 12.131.183.66 12.189.234.28 12.221.147.37 12.202.180.173 12.202.180.215 12.221.147.17 12.221.147.13 12.221.147.36 12.221.147.34 12.221.147.57 12.202.180.222 12.202.180.224 12.221.147.21 12.221.147.35 12.221.147.39 12.221.147.52 12.202.180.220 12.216.111.84