2.57.121.17

Classification: Malicious

2.57.121.17 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-03. Network: AS47890 UNMANAGED LTD.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2026-03-17 10:05:16 2026-09-03 14:01:38 attacker malicious-activity
Malicious Host AbuseIPDB 2026-03-15 23:16:41 2026-06-01 19:41:44 compromised malicious-activity
SIP Attacker Blocklist.de 2026-05-05 09:00:03 2026-05-06 09:00:03 malicious-activity
Malicious Host HoneyDB 2021-11-08 00:00:00 2026-04-14 00:00:00 malicious-activity
SSH Attacker AbuseIPDB 2026-03-18 12:04:22 2026-03-22 21:52:21 malicious-activity
Bruteforce AbuseIPDB 2026-03-18 12:04:17 2026-03-22 21:52:21 malicious-activity
Port Scanner AbuseIPDB 2026-03-18 12:04:17 2026-03-22 21:34:26 anomalous-activity
HTTP Attacker AbuseIPDB 2026-03-18 13:36:18 2026-03-22 21:09:58 malicious-activity
Hacking AbuseIPDB 2026-03-18 12:04:22 2026-03-22 20:46:57 malicious-activity
DNS Compromise AbuseIPDB 2026-03-19 01:04:59 2026-03-22 20:20:03 compromised
DNS Poisoning AbuseIPDB 2026-03-19 01:04:59 2026-03-22 20:20:03 compromised
DDoS Attacker AbuseIPDB 2026-03-18 23:27:06 2026-03-22 20:20:03 malicious-activity
Known Attacker AbuseIPDB 2026-03-18 23:27:06 2026-03-22 20:20:03 malicious-activity
Mail Spammer AbuseIPDB 2026-03-18 16:00:47 2026-03-22 20:20:03 malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-18 15:50:18 2026-03-22 20:20:03 anomalous-activity
FTP Attacker AbuseIPDB 2026-03-18 15:49:51 2026-03-22 19:12:57 malicious-activity
Phishing AbuseIPDB 2026-03-18 16:00:47 2026-03-21 05:17:02 malicious-activity
IMAP Attacker AbuseIPDB 2026-03-18 16:00:47 2026-03-21 03:25:57 malicious-activity
VPN AbuseIPDB 2026-03-20 11:29:01 2026-03-20 11:29:01 anonymization
Malicious Host CIArmy 2021-11-09 00:52:34 2021-12-10 04:35:07 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2021-11-11 01:55:35 2021-12-09 04:51:17 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2021-11-11 01:55:32 2021-12-09 04:51:14 malicious-activity

Tags

ssh bruteforce bot sip attacker

Whois information

AS name
AS47890 UNMANAGED LTD
AS registry
ripencc
AS date
2019-03-19 00:00:00
AS CIDR
2.57.121.0/24
Registrant
UNMANAGED LTD
City
Timisoara
Postal code
300574
Country
RO — Romania 🇷🇴
First indexed
2021-11-09 00:52:34
Last updated
2026-09-03 14:01:41

Malicious IPs in the same CIDR

2.57.121.86 2.57.121.50 2.57.121.112 2.57.121.25 2.57.121.118 2.57.121.69 2.57.121.120 2.57.121.17