191.96.106.28

Classification: Malicious

191.96.106.28 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-12. Network: AS174 Private Customer.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • VPN node β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2025-06-08 14:51:13 2026-09-12 01:25:34 anonymization vpn
HTTP Spammer StopForumSpam.com 2023-11-04 21:48:10 2026-09-09 07:42:44 attacker malicious-activity
Malicious Host HoneyDB 2026-05-25 00:00:00 2026-05-25 00:00:00 malicious-activity
HTTP Spammer GPF DNS Blocklist 2025-06-08 14:51:12 2026-05-02 08:14:11 malicious-activity
Mail Spammer Abuseat.org 2023-11-04 21:48:10 2023-11-04 21:48:10

Tags

bot abuse

Whois information

AS name
AS174 Private Customer
AS registry
ripencc
AS date
2014-03-13 00:00:00
AS CIDR
191.96.106.0/24
Registrant
Private Customer
City
Los Angeles
State
CA
Postal code
90096
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2023-11-04 21:48:10
Last updated
2026-09-12 01:25:35

Malicious IPs in the same CIDR

191.96.106.184 191.96.106.213 191.96.106.159 191.96.106.189 191.96.106.146 191.96.106.25 191.96.106.199 191.96.106.191 191.96.106.139 191.96.106.212 191.96.106.219 191.96.106.131 191.96.106.197 191.96.106.60 191.96.106.66 191.96.106.69 191.96.106.28 191.96.106.162 191.96.106.63 191.96.106.39 191.96.106.59 191.96.106.50 191.96.106.153 191.96.106.14 191.96.106.148