172.104.237.140

Classification: Malicious

172.104.237.140 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-01. Network: AS63949 Linode.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2025-02-16 01:16:48 2026-09-01 08:50:32 attacker malicious-activity
DNS Server Public-dns.info 2023-03-18 12:29:03 2026-09-01 02:24:52 benign
SSH Attacker Blocklist.net.ua 2023-07-14 06:53:23 2024-01-13 07:28:19 malicious-activity
SSH Attacker Blocklist.de 2023-07-01 04:23:44 2023-07-03 04:16:44 malicious-activity
Mail Spammer Abuseat.org 2020-10-11 05:27:01 2020-10-11 05:27:01
Malicious Host HoneyDB 2020-10-10 00:00:00 2020-10-10 00:00:00

Tags

dns reflection abuse ssh bruteforce bot

Whois information

AS name
AS63949 Linode
AS registry
arin
AS date
2015-06-19 00:00:00
AS CIDR
172.104.224.0/19
CIDR
172.104.0.0/15
Registrant
Linode
Address
145 Broadway
City
Frankfurt am Main
State
MA
Postal code
60311
Country
DE — Germany 🇩🇪
Contact email
[email protected], [email protected], [email protected], [email protected]
First indexed
2020-10-11 05:27:01
Last updated
2026-09-01 08:50:33

Malicious IPs in the same CIDR

172.104.240.74 172.104.247.248 172.104.237.140 172.104.243.155 172.104.236.166 172.104.234.47 172.104.235.161 172.104.239.9 172.104.244.71