189.7.125.227
Classification: Malicious
189.7.125.227 is a malicious IP address. Reported by 4 threat sources, last seen 2026-09-02. Network: AS28573 CLARO S A.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malicious Host | CIArmy | 2026-08-16 20:04:02 | 2026-09-02 20:03:42 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-08-19 09:16:46 | 2026-08-31 09:15:48 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-08-19 09:16:44 | 2026-08-31 09:15:46 | malicious-activity | |
| Mail Spammer | Barracuda | 2019-09-02 09:06:26 | 2019-09-02 09:06:26 | ||
| NTP Open Resolver | Rapid7 Open Data | 2019-08-05 02:52:20 | 2019-09-02 04:35:41 |
Tags
ntp reflection amplification open resolver monlistWhois information
- AS name
- AS28573 CLARO S A
- AS registry
- lacnic
- AS date
- 2006-09-06 00:00:00
- AS CIDR
- 189.7.120.0/21
- CIDR
- 189.4.0.0/14
- Registrant
- CLARO S.A.
- City
- Santa Maria
- Country
- BR — Brazil 🇧🇷
- Contact email
- [email protected], [email protected], [email protected]
- First indexed
- 2019-08-05 02:52:20
- Last updated
- 2026-09-02 20:03:42