139.60.161.213

Classification: Suspicious

139.60.161.213 is a suspicious IP address. Linked to Cobalt Strike malware. Reported by 1 threat source, last seen 2022-05-30. Network: AS395839 HOSTKEY.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Cobalt Strike ThreatFox Abuse.ch 2022-02-21 00:01:56 2022-05-30 20:18:36 malicious-activity S0154 Cobalt Strike

Tags

cobaltstrike hostkey agentemis beacon port:443 port:80

Whois information

AS name
AS395839 HOSTKEY
AS registry
arin
AS date
2017-02-07 00:00:00
AS CIDR
139.60.161.0/24
CIDR
139.60.160.0/22
Registrant
HOSTKEY
Address
122 East 42nd Street Suite 3900
City
New York
State
NY
Postal code
10000
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected]
First indexed
2022-02-21 00:01:56
Last updated
2026-01-15 01:11:40