12.189.234.28
Classification: Malicious
12.189.234.28 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-10. Network: AS7018 AT&T Enterprises, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- IoT threat — Seen attacking IoT devices.
- Open proxy — Provides anonymization that can hide an attacker.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SSH Attacker | Blocklist.net.ua | 2025-03-24 13:40:43 | 2026-09-10 16:02:27 | attacker malicious-activity | |
| Empty reason | Blocklist.net.ua | 2026-09-04 16:03:22 | 2026-09-04 16:03:22 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-11-27 00:15:01 | 2026-06-05 00:02:29 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2024-11-26 21:13:02 | 2026-03-23 19:05:46 | compromised malicious-activity | |
| Bruteforce | AbuseIPDB | 2024-11-21 10:24:05 | 2026-02-22 01:08:54 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2024-11-12 03:01:15 | 2026-02-22 01:08:54 | malicious-activity | |
| Hacking | AbuseIPDB | 2024-11-12 03:01:15 | 2026-02-07 22:58:08 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2024-11-21 10:24:05 | 2026-02-07 15:00:17 | anomalous-activity | |
| SSH Attacker | Blocklist.de | 2025-03-22 13:57:22 | 2026-02-07 10:04:18 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-02-04 05:00:59 | 2026-02-05 05:01:50 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-01-17 02:06:31 | 2026-02-05 03:01:26 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2024-11-21 10:24:05 | 2026-02-04 23:27:58 | malicious-activity | |
| Malicious Host | HoneyDB | 2025-10-15 00:00:00 | 2026-02-03 00:00:00 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2025-03-04 13:08:30 | 2026-01-31 10:29:10 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2024-11-21 10:24:05 | 2026-01-25 02:47:13 | anomalous-activity | |
| DDoS Attacker | AbuseIPDB | 2025-07-10 09:24:35 | 2026-01-22 18:09:19 | malicious-activity | |
| Phishing | AbuseIPDB | 2024-11-29 18:00:05 | 2026-01-14 02:16:36 | malicious-activity | |
| Mail Spammer | AbuseIPDB | 2024-11-28 21:03:56 | 2026-01-14 02:16:36 | malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2024-11-30 04:20:02 | 2026-01-14 02:16:36 | malicious-activity | |
| Known Attacker | AbuseIPDB | 2025-01-01 06:23:52 | 2025-12-17 04:38:03 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2025-02-18 04:58:05 | 2025-12-08 07:38:09 | malicious-activity | |
| IoT Attacker | AbuseIPDB | 2025-03-22 02:10:58 | 2025-12-08 07:38:09 | malicious-activity | |
| DNS Compromise | AbuseIPDB | 2025-03-04 13:08:30 | 2025-12-08 04:27:17 | compromised | |
| DNS Poisoning | AbuseIPDB | 2025-03-22 02:10:58 | 2025-12-08 04:27:17 | compromised | |
| VPN | AbuseIPDB | 2025-03-22 02:10:58 | 2025-10-13 14:00:54 | anonymization | |
| SSH Attacker | Blocklist.de SSH | 2025-10-06 14:16:22 | 2025-10-08 08:03:04 | malicious-activity | |
| SIP Attacker | AbuseIPDB | 2025-03-22 02:10:58 | 2025-09-20 22:02:09 | malicious-activity | |
| Proxy | AbuseIPDB | 2025-03-22 02:10:58 | 2025-09-20 22:02:09 | anonymization | |
| Brute force passwords using SSH on server CheckNet | Blocklist.net.ua | 2025-03-27 15:14:10 | 2025-07-22 09:01:47 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2024-12-11 08:22:21 | 2025-06-12 13:36:22 | malicious-activity | |
| Mail Spammer | Blocklist.de | 2024-11-30 10:10:07 | 2025-03-25 13:24:22 | malicious-activity | |
| IMAP Attacker | Blocklist.de | 2024-11-27 09:41:17 | 2025-03-25 13:05:26 | malicious-activity |
Tags
attacker imap pop3 sasl bot mail spam ssh bruteforce abuse apache ddos rfi login joomla wordpressWhois information
- AS name
- AS7018 AT&T Enterprises, LLC
- AS registry
- arin
- AS date
- 1983-08-23 00:00:00
- AS CIDR
- 12.128.0.0/9
- CIDR
- 12.0.0.0/8
- Registrant
- AT&T Enterprises, LLC
- Address
- 200 S. Laurel AVE.
- City
- Florence
- State
- AL
- Postal code
- 35630
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2024-11-27 04:13:09
- Last updated
- 2026-09-10 16:02:27
Malicious IPs in the same CIDR
12.221.147.17 12.221.147.13 12.221.147.36 12.221.147.34 12.218.209.130 12.203.54.178 12.154.48.194 12.131.14.114 12.131.183.66 12.189.234.28 12.156.67.18 12.221.147.57 12.202.180.173 12.202.180.222 12.202.180.224 12.221.147.21 12.221.147.35 12.221.147.39 12.221.147.52 12.202.180.215 12.202.180.220 12.216.111.84 12.221.147.25 12.221.147.27 12.221.147.31