149.56.20.131

Classification: Malicious

149.56.20.131 is a malicious IP address. Reported by 7 threat sources, last seen 2026-08-29. Network: AS16276 OVH Hosting, Inc..

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2025-02-07 01:45:43 2026-08-29 18:22:47 attacker malicious-activity
HTTP Spammer StopForumSpam.com 2025-01-26 00:55:58 2025-06-25 21:25:05 malicious-activity
VPN IPWhois.io 2025-04-13 03:27:17 2025-06-15 00:46:09 anonymization
Suspicious Host AbuseIPDB 2024-08-25 01:40:17 2025-05-26 15:55:37 anomalous-activity
Malicious Host AbuseIPDB 2024-08-24 19:07:41 2025-04-16 18:14:32 compromised malicious-activity
SQL Injection AbuseIPDB 2024-10-07 22:35:05 2025-04-12 18:31:51 malicious-activity
HTTP Scrapper AbuseIPDB 2024-08-24 15:10:31 2025-04-12 18:31:51 anomalous-activity
DDoS attack AbuseIPDB 2024-10-07 22:35:05 2025-04-12 18:31:51 malicious-activity
Bruteforce AbuseIPDB 2024-08-24 00:15:05 2025-04-12 18:31:51 malicious-activity
HTTP Attacker AbuseIPDB 2024-08-23 22:53:23 2025-04-12 18:31:51 malicious-activity
Proxy IPWhois.io 2025-02-07 01:45:43 2025-04-04 06:36:26 anonymization
SSH Attacker AbuseIPDB 2024-08-24 00:15:05 2025-04-02 05:51:44 malicious-activity
Hacking AbuseIPDB 2024-08-24 19:07:41 2025-03-31 09:28:14 malicious-activity
Port Scanner AbuseIPDB 2024-08-31 15:02:02 2025-03-17 23:43:30 anomalous-activity
Bruteforce login attacker Blocklist.de 2024-11-27 09:36:11 2025-03-12 14:30:45 malicious-activity
HTTP Attacker Blocklist.de 2024-11-26 08:40:12 2025-03-12 13:21:48 malicious-activity
DDoS Attacker Blocklist.net.ua 2024-09-03 16:34:21 2025-03-02 22:31:02 malicious-activity
Mail Spammer AbuseIPDB 2024-09-15 16:22:56 2025-02-23 23:20:17 malicious-activity
HTTP Spammer Cleantalk.org 2025-01-14 00:34:53 2025-01-14 00:34:53 malicious-activity
HTTP bot Blocklist.de 2024-11-23 09:22:33 2024-11-24 08:47:54 malicious-activity

Tags

abuse attacker spam bruteforce bot apache ddos rfi login joomla wordpress

Whois information

AS name
AS16276 OVH Hosting, Inc.
AS registry
arin
AS date
2016-02-09 00:00:00
AS CIDR
149.56.0.0/16
CIDR
149.56.0.0/16
Registrant
OVH Hosting, Inc.
Address
800-1801 McGill College
City
Montreal
State
QC
Postal code
H3A 2B7
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2024-08-25 05:42:48
Last updated
2026-08-29 18:22:48

Malicious IPs in the same CIDR

149.56.44.47 149.56.13.232 149.56.45.200 149.56.150.107 149.56.110.191 149.56.22.133 149.56.160.248 149.56.126.142 149.56.160.214 149.56.160.191 149.56.179.95 149.56.20.131 149.56.244.85 149.56.12.189