2.57.121.17
Classification: Malicious
2.57.121.17 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-03. Network: AS47890 UNMANAGED LTD.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SSH Attacker | Blocklist.de | 2026-03-17 10:05:16 | 2026-09-03 14:01:38 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-03-15 23:16:41 | 2026-06-01 19:41:44 | compromised malicious-activity | |
| SIP Attacker | Blocklist.de | 2026-05-05 09:00:03 | 2026-05-06 09:00:03 | malicious-activity | |
| Malicious Host | HoneyDB | 2021-11-08 00:00:00 | 2026-04-14 00:00:00 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-03-18 12:04:22 | 2026-03-22 21:52:21 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-03-18 12:04:17 | 2026-03-22 21:52:21 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-03-18 12:04:17 | 2026-03-22 21:34:26 | anomalous-activity | |
| HTTP Attacker | AbuseIPDB | 2026-03-18 13:36:18 | 2026-03-22 21:09:58 | malicious-activity | |
| Hacking | AbuseIPDB | 2026-03-18 12:04:22 | 2026-03-22 20:46:57 | malicious-activity | |
| DNS Compromise | AbuseIPDB | 2026-03-19 01:04:59 | 2026-03-22 20:20:03 | compromised | |
| DNS Poisoning | AbuseIPDB | 2026-03-19 01:04:59 | 2026-03-22 20:20:03 | compromised | |
| DDoS Attacker | AbuseIPDB | 2026-03-18 23:27:06 | 2026-03-22 20:20:03 | malicious-activity | |
| Known Attacker | AbuseIPDB | 2026-03-18 23:27:06 | 2026-03-22 20:20:03 | malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-03-18 16:00:47 | 2026-03-22 20:20:03 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-03-18 15:50:18 | 2026-03-22 20:20:03 | anomalous-activity | |
| FTP Attacker | AbuseIPDB | 2026-03-18 15:49:51 | 2026-03-22 19:12:57 | malicious-activity | |
| Phishing | AbuseIPDB | 2026-03-18 16:00:47 | 2026-03-21 05:17:02 | malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2026-03-18 16:00:47 | 2026-03-21 03:25:57 | malicious-activity | |
| VPN | AbuseIPDB | 2026-03-20 11:29:01 | 2026-03-20 11:29:01 | anonymization | |
| Malicious Host | CIArmy | 2021-11-09 00:52:34 | 2021-12-10 04:35:07 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2021-11-11 01:55:35 | 2021-12-09 04:51:17 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2021-11-11 01:55:32 | 2021-12-09 04:51:14 | malicious-activity |
Tags
ssh bruteforce bot sip attackerWhois information
- AS name
- AS47890 UNMANAGED LTD
- AS registry
- ripencc
- AS date
- 2019-03-19 00:00:00
- AS CIDR
- 2.57.121.0/24
- Registrant
- UNMANAGED LTD
- City
- Timisoara
- Postal code
- 300574
- Country
- RO — Romania 🇷🇴
- First indexed
- 2021-11-09 00:52:34
- Last updated
- 2026-09-03 14:01:41
Malicious IPs in the same CIDR
2.57.121.86 2.57.121.50 2.57.121.112 2.57.121.25 2.57.121.118 2.57.121.69 2.57.121.120 2.57.121.17