189.7.125.227

Classification: Malicious

189.7.125.227 is a malicious IP address. Reported by 4 threat sources, last seen 2026-09-02. Network: AS28573 CLARO S A.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malicious Host CIArmy 2026-08-16 20:04:02 2026-09-02 20:03:42 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-08-19 09:16:46 2026-08-31 09:15:48 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-08-19 09:16:44 2026-08-31 09:15:46 malicious-activity
Mail Spammer Barracuda 2019-09-02 09:06:26 2019-09-02 09:06:26
NTP Open Resolver Rapid7 Open Data 2019-08-05 02:52:20 2019-09-02 04:35:41

Tags

ntp reflection amplification open resolver monlist

Whois information

AS name
AS28573 CLARO S A
AS registry
lacnic
AS date
2006-09-06 00:00:00
AS CIDR
189.7.120.0/21
CIDR
189.4.0.0/14
Registrant
CLARO S.A.
City
Santa Maria
Country
BR — Brazil 🇧🇷
Contact email
[email protected], [email protected], [email protected]
First indexed
2019-08-05 02:52:20
Last updated
2026-09-02 20:03:42

Malicious IPs in the same CIDR

189.7.125.227