12.139.38.4

Classification: Malicious

12.139.38.4 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-12. Network: AS7018 AT&T Enterprises, LLC.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Known scanner β€” Seen scanning hosts over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2022-07-20 02:06:50 2026-09-12 14:00:55 attacker malicious-activity
Bruteforce AbuseIPDB 2025-04-15 22:03:37 2026-09-07 04:31:44 attacker malicious-activity
Port Scanner AbuseIPDB 2025-02-08 22:13:26 2026-09-06 19:50:29 anomalous-activity attacker malicious-activity reconnaissance
SSH Attacker AbuseIPDB 2025-04-15 22:03:37 2026-09-06 19:50:29 attacker malicious-activity
SSH Attacker Blocklist.net.ua 2025-04-17 16:03:37 2026-09-05 16:01:58 attacker malicious-activity
Malicious Host AbuseIPDB 2024-11-18 20:55:35 2026-09-04 20:10:18 attacker compromised malicious-activity
Hacking AbuseIPDB 2025-04-17 10:16:04 2026-09-03 06:08:58 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-09-02 12:33:24 2026-09-02 12:33:24 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-09-02 12:33:24 2026-09-02 12:33:24 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2025-04-17 10:16:04 2026-09-02 12:33:24 anomalous-activity attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-06-15 05:07:22 2026-09-02 12:33:24 attacker malicious-activity
FTP Attacker Blocklist.de 2026-06-15 10:00:06 2026-06-15 10:00:06 malicious-activity
FTP Attacker AbuseIPDB 2026-06-14 14:50:16 2026-06-14 14:50:16 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-11-17 01:48:17 2026-06-07 19:33:56 anomalous-activity
Bruteforce Maltiverse 2022-10-01 17:53:25 2022-12-27 13:54:28 malicious-activity
Port Scanner Maltiverse 2022-10-29 02:24:42 2022-12-27 13:25:16 anomalous-activity
SSH Attacker Maltiverse 2022-10-01 17:53:25 2022-12-27 13:25:16 malicious-activity
Hacking Maltiverse 2022-10-01 17:53:25 2022-10-01 17:53:25 malicious-activity
HTTP Spammer StopForumSpam.com 2022-05-22 03:15:03 2022-07-27 03:38:52 malicious-activity

Tags

ssh bruteforce bot abuse attacker ftp

Whois information

AS name
AS7018 AT&T Enterprises, LLC
AS registry
arin
AS date
1983-08-23 00:00:00
AS CIDR
12.128.0.0/9
CIDR
12.0.0.0/8
Registrant
AT&T Enterprises, LLC
Address
200 S. Laurel AVE.
City
Los Angeles
State
CA
Postal code
90012
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
First indexed
2022-05-22 03:15:03
Last updated
2026-09-12 14:00:55

Malicious IPs in the same CIDR

12.156.67.18 12.202.180.216 12.139.38.4 12.218.209.130 12.154.48.194 12.203.54.178 12.131.14.114 12.131.183.66 12.189.234.28 12.221.147.37 12.202.180.173 12.202.180.215 12.221.147.17 12.221.147.13 12.221.147.36 12.221.147.34 12.221.147.57 12.202.180.222 12.202.180.224 12.221.147.21 12.221.147.35 12.221.147.39 12.221.147.52 12.202.180.220 12.216.111.84