194.180.48.225
Classification: Malicious
194.180.48.225 is a malicious IP address. Linked to Redline Stealer malware. Reported by 5 threat sources, last seen 2026-08-26. Network: AS201814 HostSlick.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
MITRE ATT&CK associations
Malware families: REDLINE STEALER (S1240)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2023-01-07 09:17:44 | 2026-08-26 07:39:13 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-07-16 20:25:28 | 2026-08-26 00:34:13 | anomalous-activity attacker malicious-activity reconnaissance | |
| Hacking | AbuseIPDB | 2026-07-16 20:25:28 | 2026-08-26 00:34:13 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-07-24 04:21:00 | 2026-08-24 01:02:25 | attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-07-16 20:25:28 | 2026-08-24 01:02:25 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-07-18 11:15:31 | 2026-08-22 09:16:54 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-07-18 11:15:29 | 2026-08-22 09:16:52 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-07-16 20:25:28 | 2026-08-20 04:40:45 | anomalous-activity attacker malicious-activity | |
| Malicious Host | CIArmy | 2025-08-02 16:07:44 | 2026-08-18 20:04:16 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-07-27 07:08:00 | 2026-07-28 07:08:03 | attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2026-07-26 03:35:08 | 2026-07-26 03:35:08 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-08-02 00:32:42 | 2025-10-12 15:47:34 | anomalous-activity | |
| RedLine Stealer | ThreatFox Abuse.ch | 2023-01-07 09:17:43 | 2023-01-09 08:20:30 | malicious-activity | S1240 RedLine Stealer |
Tags
redlinestealer port:80Whois information
- AS name
- AS201814 HostSlick
- AS registry
- ripencc
- AS date
- 2018-05-31 00:00:00
- AS CIDR
- 194.180.48.0/24
- CIDR
- 194.180.48.0/24
- Registrant
- HostSlick
- Address
- Krammer 8 3232HE Brielle NETHERLANDS
- City
- Warsaw
- Postal code
- 00-693
- Country
- PL — Poland 🇵🇱
- Contact email
- [email protected]
- First indexed
- 2023-01-07 09:17:43
- Last updated
- 2026-08-26 07:39:15
Malicious IPs in the same CIDR
194.180.48.131 194.180.48.243 194.180.48.215 194.180.48.247 194.180.48.31 194.180.48.21 194.180.48.138 194.180.48.7 194.180.48.130 194.180.48.148 194.180.48.139 194.180.48.225 194.180.48.237 194.180.48.211 194.180.48.223 194.180.48.249 194.180.48.156 194.180.48.239 194.180.48.154 194.180.48.213 194.180.48.41 194.180.48.23