193.106.175.140
Classification: Malicious
193.106.175.140 is a malicious IP address. Linked to Socgholish malware. Reported by 4 threat sources, last seen 2026-09-03. Network: AS50465 IQHost Ltd.
Current activity
- Known attacker — Seen launching attacks over the Internet.
MITRE ATT&CK associations
Malware families: SOCGHOLISH (S1124)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2026-09-03 02:55:29 | 2026-09-03 02:55:29 | attacker malicious-activity | |
| FAKEUPDATES | ThreatFox Abuse.ch | 2024-04-17 05:19:52 | 2024-04-19 04:24:30 | malicious-activity | S1124 SocGholish |
| Mail Spammer | Blocklist.de | 2020-10-07 02:44:58 | 2020-10-11 09:53:12 | ||
| NTP Open Resolver | Rapid7 Open Data | 2018-12-03 06:01:24 | 2019-09-02 03:50:43 |
Tags
ntp reflection amplification open resolver monlist mail spam keitarotds socgholish port:443 fakeupdateWhois information
- AS name
- AS50465 IQHost Ltd
- AS registry
- ripencc
- AS date
- 2010-01-12 00:00:00
- AS CIDR
- 193.106.175.0/24
- CIDR
- 193.106.172.0/22
- Registrant
- IQHost Ltd
- Address
- Russian federation, 125284 Moscow, Begovaya, 15, office 22
- City
- Moscow
- Postal code
- 109012
- Country
- RU — Russian Federation 🇷🇺
- First indexed
- 2018-12-03 06:01:24
- Last updated
- 2026-09-03 02:55:30