173.239.216.21

Classification: Malicious

173.239.216.21 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-05. Network: AS206092 LogicWeb Inc..

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2025-05-22 06:41:00 2026-09-05 07:01:15 anonymization vpn
Bruteforce login attacker Blocklist.de 2026-08-06 09:00:16 2026-08-07 09:00:53 attacker malicious-activity
HTTP Attacker Blocklist.de 2026-08-06 07:00:15 2026-08-07 07:00:53 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-07-15 22:23:25 2026-05-07 02:47:20 anomalous-activity
HTTP Spammer Sblam 2025-05-19 07:23:45 2025-05-22 06:40:58 malicious-activity
Proxy IPWhois.io 2025-05-02 14:09:43 2025-05-02 14:09:43 anonymization
HTTP Spammer StopForumSpam.com 2023-12-15 05:13:14 2024-08-29 04:45:25 malicious-activity
HTTP Spammer Cleantalk.org 2017-10-16 08:32:52 2024-08-02 18:16:10 malicious-activity

Tags

abuse bot apache ddos rfi attacker login bruteforce joomla wordpress

Whois information

AS name
AS206092 LogicWeb Inc.
AS registry
arin
AS date
2010-05-06 00:00:00
AS CIDR
173.239.208.0/20
CIDR
173.239.192.0/18
Registrant
LogicWeb Inc.
Address
4509 Steeplechase Dr.
City
Bern
State
PA
Postal code
3011
Country
CH — Switzerland 🇨🇭
Contact email
[email protected], [email protected]
First indexed
2017-10-16 08:32:52
Last updated
2026-09-05 07:01:16

Malicious IPs in the same CIDR

173.239.214.14 173.239.214.13 173.239.216.12 173.239.216.20 173.239.214.6 173.239.216.13 173.239.220.5 173.239.216.28 173.239.221.8 173.239.216.4 173.239.214.2 173.239.214.10 173.239.214.17 173.239.214.15 173.239.214.16 173.239.214.12 173.239.214.18 173.239.214.5 173.239.216.21 173.239.216.3 173.239.216.25 173.239.216.26