172.104.237.140
Classification: Malicious
172.104.237.140 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-01. Network: AS63949 Linode.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2025-02-16 01:16:48 | 2026-09-01 08:50:32 | attacker malicious-activity | |
| DNS Server | Public-dns.info | 2023-03-18 12:29:03 | 2026-09-01 02:24:52 | benign | |
| SSH Attacker | Blocklist.net.ua | 2023-07-14 06:53:23 | 2024-01-13 07:28:19 | malicious-activity | |
| SSH Attacker | Blocklist.de | 2023-07-01 04:23:44 | 2023-07-03 04:16:44 | malicious-activity | |
| Mail Spammer | Abuseat.org | 2020-10-11 05:27:01 | 2020-10-11 05:27:01 | ||
| Malicious Host | HoneyDB | 2020-10-10 00:00:00 | 2020-10-10 00:00:00 |
Tags
dns reflection abuse ssh bruteforce botWhois information
- AS name
- AS63949 Linode
- AS registry
- arin
- AS date
- 2015-06-19 00:00:00
- AS CIDR
- 172.104.224.0/19
- CIDR
- 172.104.0.0/15
- Registrant
- Linode
- Address
- 145 Broadway
- City
- Frankfurt am Main
- State
- MA
- Postal code
- 60311
- Country
- DE — Germany 🇩🇪
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2020-10-11 05:27:01
- Last updated
- 2026-09-01 08:50:33
Malicious IPs in the same CIDR
172.104.240.74 172.104.247.248 172.104.237.140 172.104.243.155 172.104.236.166 172.104.234.47 172.104.235.161 172.104.239.9 172.104.244.71