198.235.24.80

Classification: Malicious

198.235.24.80 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-13. Network: AS396982 Palo Alto Networks, Inc.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Unauthorized scanning of hosts Blocklist.net.ua 2024-12-13 12:23:17 2026-09-13 17:23:22 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-11 17:26:04 2026-09-11 17:26:04 attacker malicious-activity
Unknown malware ThreatFox Abuse.ch 2026-09-04 23:14:54 2026-09-04 23:25:21 malicious-activity
Malicious Host AbuseIPDB 2026-05-22 23:04:26 2026-05-22 23:04:26 malicious-activity
Suspicious Host AbuseIPDB 2026-05-21 00:04:14 2026-05-21 00:04:14 anomalous-activity
SSH Attacker Blocklist.de 2023-07-10 04:15:46 2026-03-30 10:02:19 malicious-activity
Mail Spammer Blocklist.de 2024-06-17 03:26:13 2026-01-07 06:47:51 malicious-activity
IMAP Attacker Blocklist.de 2025-07-23 07:28:13 2025-07-24 07:25:33 malicious-activity
HTTP Attacker Blocklist.de 2024-08-05 08:12:10 2024-10-18 09:34:24 malicious-activity
Malicious Host HoneyDB 2023-04-14 00:00:00 2024-04-29 00:00:00 malicious-activity

Tags

ssh bruteforce bot mail spam apache ddos rfi attacker abuse imap pop3 sasl port:52483 suricata t-pot

Whois information

AS name
AS396982 Palo Alto Networks, Inc
AS registry
arin
AS date
2021-12-20 00:00:00
AS CIDR
198.235.24.0/24
CIDR
198.235.24.0/24
Registrant
Palo Alto Networks, Inc
Address
Palo Alto Networks 3000 Tannery Way Santa Clara, CA 95054
City
Taipei
State
CA
Postal code
110
Country
TW — Taiwan, Province of China 🇹🇼
Contact email
[email protected], [email protected]
First indexed
2023-04-15 11:34:16
Last updated
2026-09-13 17:23:24

Malicious IPs in the same CIDR

198.235.24.248 198.235.24.205 198.235.24.208 198.235.24.225 198.235.24.192 198.235.24.128 198.235.24.80 198.235.24.25