185.107.56.235

Classification: Malicious

185.107.56.235 is a malicious IP address. Linked to Proton malware. Reported by 2 threat sources, last seen 2026-09-03.

Current activity

  • VPN node — Provides anonymization that can hide an attacker.

MITRE ATT&CK associations

Malware families: PROTON (S0279)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2026-06-29 19:12:36 2026-09-03 01:40:39 anonymization vpn
VPN ProtonVPN Maltiverse Threat Observatory 2026-07-07 09:43:06 2026-09-02 09:46:07 anomalous-activity anonymization country_code:br industry:education-and-nonprofits malicious-activity vpn
Proton Maltiverse Threat Observatory 2026-06-26 09:43:28 2026-06-27 09:45:52 S0279 Proton

Tags

port:1194

Whois information

AS name
AS43350 Nforce Entertainment B.V.
Registrant
Nforce Entertainment B.V.
City
Roosendaal
Postal code
4701 GK
Country
NL — Netherlands 🇳🇱
First indexed
2026-06-29 19:12:35
Last updated
2026-09-03 01:40:40