205.185.122.49

Classification: Malicious

205.185.122.49 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 6 threat sources, last seen 2026-09-01.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • VPN node β€” Provides anonymization that can hide an attacker.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
HTTP Spammer StopForumSpam.com 2026-08-25 07:12:41 2026-09-01 07:35:20 malicious-activity
VPN IPWhois.io 2025-02-13 11:56:53 2026-08-15 15:12:15 anonymization vpn
Mail Spammer Barracuda 2022-09-09 20:19:15 2026-08-15 15:12:15 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-07-14 06:03:07 2025-06-24 16:24:17 anomalous-activity
Malicious Host AbuseIPDB 2024-08-04 17:11:02 2024-08-16 00:03:27 malicious-activity
Malicious Host CIArmy 2024-08-02 18:09:49 2024-08-10 19:24:43 malicious-activity
Cobalt Strike ThreatFox Abuse.ch 2022-09-09 20:19:12 2022-09-12 19:18:35 malicious-activity S0154 Cobalt Strike

Tags

cobaltstrike ponynet port:443 agentemis beacon cobeacon port:80 bot abuse

Whois information

AS name
AS53667 Frantech Solutions
AS registry
arin
AS date
2010-09-03 00:00:00
AS CIDR
205.185.112.0/20
CIDR
205.185.112.0/20
Registrant
Frantech Solutions
Address
1621 Central Ave
City
Las Vegas
State
NV
Postal code
89101
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected]
First indexed
2022-09-09 20:19:12
Last updated
2026-09-01 07:35:20

Malicious IPs in the same CIDR

205.185.126.219 205.185.125.154 205.185.113.8 205.185.117.149 205.185.121.170 205.185.116.34 205.185.127.86 205.185.124.164 205.185.124.176 205.185.127.174 205.185.122.27 205.185.125.239 205.185.127.250 205.185.121.177 205.185.122.204 205.185.113.180 205.185.126.121 205.185.123.125 205.185.118.81 205.185.121.115 205.185.126.29 205.185.122.49 205.185.120.144 205.185.122.242 205.185.122.174