185.223.152.85
Classification: Malicious
185.223.152.85 is a malicious IP address. Reported by 7 threat sources, last seen 2026-08-28. Network: AS396356 Invermae Solutions SL.
Current activity
- Known attacker β Seen launching attacks over the Internet.
- Open proxy β Provides anonymization that can hide an attacker.
- VPN node β Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| HTTP bot | Blocklist.de | 2025-09-10 07:51:20 | 2026-08-28 08:00:40 | attacker malicious-activity | |
| Proxy | IPWhois.io | 2025-03-13 08:01:19 | 2026-08-19 21:34:04 | anonymization proxy | |
| DDoS Attacker | Blocklist.net.ua | 2025-11-01 02:46:43 | 2026-07-26 16:42:33 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-03-10 00:19:58 | 2026-06-03 09:56:37 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2025-04-04 16:43:04 | 2026-05-25 10:07:48 | compromised malicious-activity | |
| HTTP Attacker | Blocklist.de | 2025-06-19 07:10:26 | 2026-03-08 03:01:09 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2025-06-19 07:49:56 | 2026-03-07 05:01:09 | malicious-activity | |
| VPN | IPWhois.io | 2025-11-12 12:38:33 | 2026-01-18 04:15:44 | anonymization | |
| Bruteforce | AbuseIPDB | 2025-03-09 21:05:09 | 2026-01-16 03:15:30 | malicious-activity | |
| Hacking | AbuseIPDB | 2025-03-14 08:56:33 | 2026-01-15 22:09:21 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-03-06 11:02:08 | 2026-01-15 21:34:30 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-03-06 17:00:16 | 2025-12-29 21:29:18 | anomalous-activity | |
| Port Scanner | AbuseIPDB | 2025-03-12 18:13:41 | 2025-12-23 09:21:48 | anomalous-activity | |
| SSH Attacker | AbuseIPDB | 2025-09-11 21:59:08 | 2025-11-27 00:42:03 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2025-09-19 10:54:06 | 2025-11-06 09:03:40 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2025-10-31 13:00:28 | 2025-10-31 13:00:28 | malicious-activity | |
| Proxy | AbuseIPDB | 2025-10-31 13:00:28 | 2025-10-31 13:00:28 | anonymization | |
| HTTP Spammer | StopForumSpam.com | 2024-08-19 06:53:04 | 2025-10-06 15:43:17 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2025-04-04 16:43:04 | 2025-08-21 22:00:41 | malicious-activity | |
| Phishing | AbuseIPDB | 2025-08-21 07:38:45 | 2025-08-21 07:38:45 | malicious-activity | |
| Proxy | FireHOL | 2023-07-04 22:36:51 | 2025-06-25 14:13:54 | anonymization | |
| DDoS attack | AbuseIPDB | 2025-04-04 10:57:50 | 2025-04-04 10:57:50 | malicious-activity | |
| Mail Spammer | Abuseat.org | 2023-07-04 22:36:53 | 2023-07-04 22:36:53 |
Tags
anonymization bot abuse apache ddos rfi attacker login bruteforce joomla wordpress spamWhois information
- AS name
- AS396356 Invermae Solutions SL
- AS registry
- ripencc
- AS date
- 2017-10-03 00:00:00
- AS CIDR
- 185.223.152.0/24
- CIDR
- 185.223.152.0/23
- Registrant
- Invermae Solutions SL
- Address
- Jacinto Gonzalez 65 2 izquierda 28600 Navalcarnero SPAIN
- City
- Los Angeles
- State
- CA
- Postal code
- 90014
- Country
- US β United States πΊπΈ
- Contact email
- [email protected]
- First indexed
- 2023-07-04 22:36:51
- Last updated
- 2026-08-28 08:00:40
Malicious IPs in the same CIDR
185.223.152.222 185.223.152.223 185.223.152.227 185.223.152.49 185.223.152.50 185.223.152.53 185.223.152.62 185.223.152.64 185.223.152.217 185.223.152.42 185.223.152.44 185.223.152.56 185.223.152.39 185.223.152.45 185.223.152.43 185.223.152.37 185.223.152.54 185.223.152.48 185.223.152.55 185.223.152.58 185.223.152.57 185.223.152.60 185.223.152.61 185.223.152.63 185.223.152.46