157.230.253.244
Classification: Malicious
157.230.253.244 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 4 threat sources, last seen 2026-08-18.
Current activity
- Command & Control server β Used by cybercriminals to control victim computers.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Cobalt Strike | ThreatFox Abuse.ch | 2025-11-18 07:37:53 | 2026-08-18 12:25:22 | botnet malicious-activity | S0154 Cobalt Strike |
| SSH Attacker | Blocklist.net.ua | 2023-07-14 06:40:41 | 2024-01-13 07:13:03 | malicious-activity | |
| SSH Attacker | Blocklist.de | 2023-06-16 04:56:33 | 2023-08-28 03:27:05 | malicious-activity | |
| Malicious Host | HoneyDB | 2023-08-19 00:00:00 | 2023-08-19 00:00:00 | malicious-activity | |
| SIP Attacker | Blocklist.de | 2023-08-06 03:37:27 | 2023-08-06 03:37:27 | malicious-activity |
Tags
abuse ssh bruteforce bot sip attacker cobeacon beacon digitalocean-asn as14061 cs-watermark-987654321 port:80 cobaltstrike censys agentemis c2 shodan port:50050Whois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2018-08-22 00:00:00
- AS CIDR
- 157.230.240.0/20
- CIDR
- 157.230.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas FL2
- City
- Singapore
- State
- NY
- Postal code
- 628459
- Country
- SG β Singapore πΈπ¬
- Contact email
- [email protected], [email protected]
- First indexed
- 2023-06-16 04:56:33
- Last updated
- 2026-08-18 14:44:37
Malicious IPs in the same CIDR
157.230.243.177 157.230.243.133 157.230.242.69 157.230.249.241 157.230.253.154 157.230.253.116 157.230.241.168 157.230.243.138 157.230.253.244