193.106.175.140

Classification: Malicious

193.106.175.140 is a malicious IP address. Linked to Socgholish malware. Reported by 4 threat sources, last seen 2026-09-03. Network: AS50465 IQHost Ltd.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: SOCGHOLISH (S1124)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2026-09-03 02:55:29 2026-09-03 02:55:29 attacker malicious-activity
FAKEUPDATES ThreatFox Abuse.ch 2024-04-17 05:19:52 2024-04-19 04:24:30 malicious-activity S1124 SocGholish
Mail Spammer Blocklist.de 2020-10-07 02:44:58 2020-10-11 09:53:12
NTP Open Resolver Rapid7 Open Data 2018-12-03 06:01:24 2019-09-02 03:50:43

Tags

ntp reflection amplification open resolver monlist mail spam keitarotds socgholish port:443 fakeupdate

Whois information

AS name
AS50465 IQHost Ltd
AS registry
ripencc
AS date
2010-01-12 00:00:00
AS CIDR
193.106.175.0/24
CIDR
193.106.172.0/22
Registrant
IQHost Ltd
Address
Russian federation, 125284 Moscow, Begovaya, 15, office 22
City
Moscow
Postal code
109012
Country
RU — Russian Federation 🇷🇺
First indexed
2018-12-03 06:01:24
Last updated
2026-09-03 02:55:30

Malicious IPs in the same CIDR

193.106.175.104 193.106.175.35 193.106.175.140