185.223.152.85

Classification: Malicious

185.223.152.85 is a malicious IP address. Reported by 7 threat sources, last seen 2026-08-28. Network: AS396356 Invermae Solutions SL.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Open proxy β€” Provides anonymization that can hide an attacker.
  • VPN node β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
HTTP bot Blocklist.de 2025-09-10 07:51:20 2026-08-28 08:00:40 attacker malicious-activity
Proxy IPWhois.io 2025-03-13 08:01:19 2026-08-19 21:34:04 anonymization proxy
DDoS Attacker Blocklist.net.ua 2025-11-01 02:46:43 2026-07-26 16:42:33 attacker malicious-activity
Suspicious Host AbuseIPDB 2025-03-10 00:19:58 2026-06-03 09:56:37 anomalous-activity
Malicious Host AbuseIPDB 2025-04-04 16:43:04 2026-05-25 10:07:48 compromised malicious-activity
HTTP Attacker Blocklist.de 2025-06-19 07:10:26 2026-03-08 03:01:09 malicious-activity
Bruteforce login attacker Blocklist.de 2025-06-19 07:49:56 2026-03-07 05:01:09 malicious-activity
VPN IPWhois.io 2025-11-12 12:38:33 2026-01-18 04:15:44 anonymization
Bruteforce AbuseIPDB 2025-03-09 21:05:09 2026-01-16 03:15:30 malicious-activity
Hacking AbuseIPDB 2025-03-14 08:56:33 2026-01-15 22:09:21 malicious-activity
HTTP Attacker AbuseIPDB 2025-03-06 11:02:08 2026-01-15 21:34:30 malicious-activity
HTTP Scrapper AbuseIPDB 2025-03-06 17:00:16 2025-12-29 21:29:18 anomalous-activity
Port Scanner AbuseIPDB 2025-03-12 18:13:41 2025-12-23 09:21:48 anomalous-activity
SSH Attacker AbuseIPDB 2025-09-11 21:59:08 2025-11-27 00:42:03 malicious-activity
DDoS Attacker AbuseIPDB 2025-09-19 10:54:06 2025-11-06 09:03:40 malicious-activity
FTP Attacker AbuseIPDB 2025-10-31 13:00:28 2025-10-31 13:00:28 malicious-activity
Proxy AbuseIPDB 2025-10-31 13:00:28 2025-10-31 13:00:28 anonymization
HTTP Spammer StopForumSpam.com 2024-08-19 06:53:04 2025-10-06 15:43:17 malicious-activity
SQL Injection AbuseIPDB 2025-04-04 16:43:04 2025-08-21 22:00:41 malicious-activity
Phishing AbuseIPDB 2025-08-21 07:38:45 2025-08-21 07:38:45 malicious-activity
Proxy FireHOL 2023-07-04 22:36:51 2025-06-25 14:13:54 anonymization
DDoS attack AbuseIPDB 2025-04-04 10:57:50 2025-04-04 10:57:50 malicious-activity
Mail Spammer Abuseat.org 2023-07-04 22:36:53 2023-07-04 22:36:53

Tags

anonymization bot abuse apache ddos rfi attacker login bruteforce joomla wordpress spam

Whois information

AS name
AS396356 Invermae Solutions SL
AS registry
ripencc
AS date
2017-10-03 00:00:00
AS CIDR
185.223.152.0/24
CIDR
185.223.152.0/23
Registrant
Invermae Solutions SL
Address
Jacinto Gonzalez 65 2 izquierda 28600 Navalcarnero SPAIN
City
Los Angeles
State
CA
Postal code
90014
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected]
First indexed
2023-07-04 22:36:51
Last updated
2026-08-28 08:00:40

Malicious IPs in the same CIDR

185.223.152.222 185.223.152.223 185.223.152.227 185.223.152.49 185.223.152.50 185.223.152.53 185.223.152.62 185.223.152.64 185.223.152.217 185.223.152.42 185.223.152.44 185.223.152.56 185.223.152.39 185.223.152.45 185.223.152.43 185.223.152.37 185.223.152.54 185.223.152.48 185.223.152.55 185.223.152.58 185.223.152.57 185.223.152.60 185.223.152.61 185.223.152.63 185.223.152.46