152.89.247.241
Classification: Suspicious
152.89.247.241 is a suspicious IP address. Linked to Bumblebee malware. Reported by 4 threat sources, last seen 2023-06-01.
MITRE ATT&CK associations
Malware families: BUMBLEBEE (S1039)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| HTTP Spammer | Cleantalk.org | 2023-06-01 07:45:32 | 2023-06-01 07:45:32 | malicious-activity | |
| ET CNC Feodo Tracker Reported CnC Server UDP | Emerging Threats | 2022-08-27 03:09:11 | 2022-09-25 02:05:17 | malicious-activity | |
| ET CNC Feodo Tracker Reported CnC Server TCP | Emerging Threats | 2022-08-27 03:09:07 | 2022-09-24 02:04:25 | malicious-activity | |
| BumbleBee | ThreatFox Abuse.ch | 2022-08-23 19:19:16 | 2022-08-25 17:18:49 | malicious-activity | S1039 Bumblebee |
| BumbleBee | FeodoTracker Abuse.ch | 2022-08-24 00:00:11 | 2022-08-24 00:00:11 | malicious-activity | S1039 Bumblebee |
Tags
c&c port:443Whois information
- AS name
- AS30823 aurologic.com cloudserver
- AS registry
- ripencc
- AS date
- 2019-01-29 00:00:00
- AS CIDR
- 152.89.244.0/22
- CIDR
- 152.89.247.0/24
- Registrant
- aurologic.com cloudserver
- Address
- combahton GmbH Network Operations Mitterfeld 47 85419 Mauern
- City
- Frankfurt
- Postal code
- 60311
- Country
- DE — Germany 🇩🇪
- Contact email
- [email protected], [email protected]
- First indexed
- 2022-08-23 19:19:16
- Last updated
- 2025-12-26 03:40:49