188.126.90.12

Classification: Suspicious

188.126.90.12 is a suspicious IP address. Linked to Dcrat malware. Reported by 2 threat sources, last seen 2026-07-18. Network: AS42708 Glesys Ab.

Current activity

  • VPN node β€” Provides anonymization that can hide an attacker.

MITRE ATT&CK associations

Malware families: DCRAT (S9017)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2026-06-06 09:25:06 2026-07-18 22:29:43 anonymization vpn
DCRat ThreatFox Abuse.ch 2026-06-06 09:00:14 2026-06-06 09:25:06 malicious-activity S9017 DCRAT

Tags

darkcrystal rat port:2003 dcrat

Whois information

AS name
AS42708 Glesys Ab
Registrant
Glesys Ab
City
Stockholm
Postal code
101 23
Country
SE β€” Sweden πŸ‡ΈπŸ‡ͺ
First indexed
2026-06-06 09:25:06
Last updated
2026-07-18 22:29:44