157.230.253.244

Classification: Malicious

157.230.253.244 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 4 threat sources, last seen 2026-08-18.

Current activity

  • Command & Control server β€” Used by cybercriminals to control victim computers.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Cobalt Strike ThreatFox Abuse.ch 2025-11-18 07:37:53 2026-08-18 12:25:22 botnet malicious-activity S0154 Cobalt Strike
SSH Attacker Blocklist.net.ua 2023-07-14 06:40:41 2024-01-13 07:13:03 malicious-activity
SSH Attacker Blocklist.de 2023-06-16 04:56:33 2023-08-28 03:27:05 malicious-activity
Malicious Host HoneyDB 2023-08-19 00:00:00 2023-08-19 00:00:00 malicious-activity
SIP Attacker Blocklist.de 2023-08-06 03:37:27 2023-08-06 03:37:27 malicious-activity

Tags

abuse ssh bruteforce bot sip attacker cobeacon beacon digitalocean-asn as14061 cs-watermark-987654321 port:80 cobaltstrike censys agentemis c2 shodan port:50050

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2018-08-22 00:00:00
AS CIDR
157.230.240.0/20
CIDR
157.230.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas FL2
City
Singapore
State
NY
Postal code
628459
Country
SG β€” Singapore πŸ‡ΈπŸ‡¬
Contact email
[email protected], [email protected]
First indexed
2023-06-16 04:56:33
Last updated
2026-08-18 14:44:37

Malicious IPs in the same CIDR

157.230.243.177 157.230.243.133 157.230.242.69 157.230.249.241 157.230.253.154 157.230.253.116 157.230.241.168 157.230.243.138 157.230.253.244