2.57.168.29

Classification: Malicious

2.57.168.29 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-02. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Known scanner β€” Seen scanning hosts over the Internet.
  • VPN node β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-03-27 12:00:19 2026-09-02 16:01:12 attacker malicious-activity
HTTP Spammer StopForumSpam.com 2022-11-28 03:06:57 2026-08-16 07:03:18 attacker malicious-activity
VPN IPWhois.io 2025-05-13 07:16:22 2026-08-12 08:29:07 anonymization vpn
Port Scanner AbuseIPDB 2026-05-17 13:00:15 2026-08-12 02:59:08 anomalous-activity attacker malicious-activity reconnaissance
Bruteforce AbuseIPDB 2026-05-17 13:00:15 2026-08-12 02:59:08 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-05-17 13:00:15 2026-08-12 02:59:08 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-05-20 20:15:35 2026-08-08 04:30:27 anomalous-activity attacker malicious-activity
SSH Attacker AbuseIPDB 2026-05-19 20:31:49 2026-08-07 23:28:06 attacker malicious-activity
Hacking AbuseIPDB 2026-05-20 03:27:42 2026-08-07 08:25:09 attacker malicious-activity
Malicious Host AbuseIPDB 2026-04-08 19:43:30 2026-07-29 05:44:37 attacker compromised malicious-activity
HTTP Attacker Blocklist.de 2026-05-25 03:00:22 2026-05-26 03:00:20 malicious-activity
Bruteforce login attacker Blocklist.de 2026-05-24 05:01:28 2026-05-25 05:00:20 malicious-activity
SQL Injection AbuseIPDB 2026-05-23 02:20:57 2026-05-23 02:20:57 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-05-21 05:17:02 2026-05-21 05:17:02 attacker malicious-activity
Suspicious Host AbuseIPDB 2025-05-12 00:49:12 2026-05-17 13:00:15 anomalous-activity
Malicious Host HoneyDB 2026-02-23 00:00:00 2026-03-23 00:00:00 malicious-activity

Tags

bot abuse attacker login bruteforce joomla wordpress apache ddos rfi

Whois information

AS name
AS396356 VPN Consumer New Jersey, United States of America
AS registry
ripencc
AS date
2019-03-19 00:00:00
AS CIDR
2.57.168.0/24
CIDR
2.57.168.0/24
Registrant
VPN Consumer New Jersey, United States of America
Address
Zweedsestraat 8a28 7418BG Deventer NETHERLANDS
City
Secaucus
State
NJ
Postal code
07094
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2022-11-28 03:06:57
Last updated
2026-09-02 16:01:13

Malicious IPs in the same CIDR

2.57.168.12 2.57.168.26 2.57.168.9 2.57.168.19 2.57.168.16 2.57.168.7 2.57.168.18 2.57.168.20 2.57.168.23 2.57.168.28 2.57.168.25 2.57.168.27 2.57.168.31 2.57.168.15 2.57.168.17 2.57.168.22 2.57.168.24 2.57.168.29 2.57.168.32 2.57.168.11 2.57.168.13 2.57.168.14 2.57.168.5 2.57.168.4 2.57.168.10