184.105.139.90
Classification: Malicious
184.105.139.90 is a malicious IP address. Reported by 8 threat sources, last seen 2026-09-12. Network: AS6939 The Shadow Server Foundation.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Empty reason | Blocklist.net.ua | 2026-09-12 16:09:19 | 2026-09-12 16:09:19 | attacker malicious-activity | |
| Unauthorized scanning of hosts | Blocklist.net.ua | 2020-07-16 09:21:31 | 2026-09-09 16:08:50 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2024-07-02 00:20:17 | 2026-06-07 17:03:36 | compromised malicious-activity | |
| Malicious Host | HoneyDB | 2019-07-12 00:00:00 | 2026-04-12 00:00:00 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2024-07-12 02:04:52 | 2026-03-21 01:42:18 | anomalous-activity | |
| HTTP Attacker | AbuseIPDB | 2024-07-12 14:09:36 | 2026-03-20 22:45:35 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2024-07-17 04:43:56 | 2026-03-20 02:02:29 | malicious-activity | |
| Hacking | AbuseIPDB | 2024-07-12 16:39:56 | 2026-03-18 04:34:33 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2024-07-16 03:02:22 | 2026-03-13 12:01:26 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2024-08-28 16:28:51 | 2026-03-07 01:02:27 | anomalous-activity | |
| SQL Injection | AbuseIPDB | 2024-11-11 18:21:01 | 2026-03-04 13:37:14 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2025-08-31 23:38:35 | 2026-02-27 02:39:05 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2024-07-17 03:06:48 | 2026-02-15 12:50:33 | malicious-activity | |
| IoT Attacker | AbuseIPDB | 2024-11-07 16:36:00 | 2026-01-21 13:37:56 | malicious-activity | |
| Mail Spammer | AbuseIPDB | 2024-07-13 02:02:26 | 2025-12-30 02:01:21 | malicious-activity | |
| Known Attacker | AbuseIPDB | 2025-02-25 04:03:25 | 2025-12-23 03:05:18 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2024-07-12 03:18:25 | 2025-06-15 18:35:03 | malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2024-07-13 02:02:26 | 2025-04-05 12:01:54 | malicious-activity | |
| Phishing | AbuseIPDB | 2024-12-02 04:37:46 | 2024-12-04 09:57:42 | malicious-activity | |
| Malicious Host | Alienvault Ip Reputation Database | 2017-10-15 09:24:04 | 2020-11-30 06:33:54 | malicious-activity | |
| Malicious Host | CIArmy | 2017-11-11 22:35:44 | 2020-11-09 02:18:39 | ||
| DDoS attack | Blocklist.net.ua | 2020-01-08 00:58:23 | 2020-07-14 03:06:00 | ||
| Scanning IPs | IBM X-Force Exchange | 2014-04-16 09:12:00 | 2020-03-29 06:52:00 | ||
| Shadowserver | Greynoise | 2018-04-26 00:00:00 | 2019-07-31 00:00:00 | ||
| Telnet attacker | Greynoise | 2019-05-17 00:00:00 | 2019-07-08 00:00:00 | ||
| Bots | IBM X-Force Exchange | 2015-12-17 19:22:00 | 2019-06-18 15:07:00 | ||
| Malicious Host | GreenSnow | 2018-02-16 13:02:25 | 2018-02-16 13:02:25 |
Tags
abuse telnet bruteforce bot researcherWhois information
- AS name
- AS6939 The Shadow Server Foundation
- AS registry
- arin
- AS date
- 2010-05-10 00:00:00
- AS CIDR
- 184.104.0.0/15
- CIDR
- 184.104.0.0/15
- Registrant
- The Shadow Server Foundation
- Address
- 760 Mission Court
- City
- Dallas
- State
- TX
- Postal code
- 75201
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected]
- First indexed
- 2017-10-15 09:24:04
- Last updated
- 2026-09-12 16:09:37
Malicious IPs in the same CIDR
184.105.139.125 184.105.139.90 184.105.139.91 184.105.139.95 184.105.139.103 184.105.139.107 184.105.139.122 184.105.247.222 184.105.247.235 184.105.247.238 184.105.139.74 184.105.139.75 184.105.139.106 184.105.139.124 184.105.247.200 184.105.247.247 184.105.139.72 184.105.247.198 184.105.247.199 184.105.247.236 184.105.247.243 184.105.139.79 184.105.139.92 184.105.139.94 184.105.139.113