194.165.16.29
Classification: Suspicious
194.165.16.29 is a suspicious IP address. Linked to Cobalt Strike malware. Reported by 6 threat sources, last seen 2025-08-08.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Cobalt Strike | ThreatFox Abuse.ch | 2025-08-06 08:18:11 | 2025-08-08 07:20:21 | malicious-activity | S0154 Cobalt Strike |
| Malicious Host | CIArmy | 2024-09-19 18:10:21 | 2025-02-09 21:11:43 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-07-17 01:55:32 | 2024-12-31 02:04:17 | anomalous-activity | |
| HTTP bot | Blocklist.de | 2024-04-07 02:34:39 | 2024-04-08 02:41:37 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2024-04-06 01:38:43 | 2024-04-06 01:38:43 | malicious-activity | |
| Gen:Variant.Midie | Hybrid-Analysis | 2021-07-07 14:30:37 | 2021-07-07 14:30:37 | ||
| SIP Attacker | Blocklist.de | 2021-04-04 09:25:21 | 2021-04-05 09:21:45 | malicious-activity | |
| Trojan.Ransom.Cerber | Hybrid-Analysis | 2021-02-08 04:30:17 | 2021-02-08 04:30:17 | ||
| Trojan.Generic | Hybrid-Analysis | 2018-09-09 14:15:57 | 2018-09-09 14:15:59 | ||
| Ransom.XW | Hybrid-Analysis | 2018-09-09 14:15:47 | 2018-09-09 14:15:47 | ||
| cerber,ransomware | Maltiverse | 2017-10-17 06:34:52 | 2017-10-17 06:34:52 |
Tags
cerber ransomware sip bruteforce bot attacker apache ddos rfi spam agentemis cobeacon cobaltstrike beacon port:80 cs-watermark-123456789Whois information
- AS name
- AS48721 Flyservers S.A.
- AS registry
- ripencc
- AS date
- 2009-01-16 00:00:00
- AS CIDR
- 194.165.16.0/24
- Registrant
- Flyservers S.A.
- City
- Kaunas
- Postal code
- 44261
- Country
- LT — Lithuania 🇱🇹
- First indexed
- 2017-10-17 06:34:52
- Last updated
- 2026-07-18 13:43:06
Malicious IPs in the same CIDR
194.165.16.5 194.165.16.166 194.165.16.162 194.165.16.164 194.165.16.165 194.165.16.161 194.165.16.167 194.165.16.163 194.165.16.11