209.99.40.222
Classification: Whitelisted
209.99.40.222 is a whitelisted (trusted) IP address. Reported by 24 threat sources, last seen 2026-07-24. Network: AS23005 SWITCH, LTD.
Current activity
- Hosting provider — Shared hosting infrastructure.
MITRE ATT&CK associations
Malware families: PONY (S0453) EMOTET (S0367) TRICKBOT (S0266)
Blacklist sightings showing the 100 most recent of 102
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Hosting Provider | Maltiverse | 2026-07-24 17:16:17 | 2026-07-24 17:16:17 | benign hosting | |
| VPN | IPWhois.io | 2025-11-14 00:47:36 | 2025-11-14 00:47:36 | anonymization | |
| Proxy | IPWhois.io | 2025-01-03 14:02:39 | 2025-01-16 11:48:08 | anonymization | |
| Raccoon | ThreatFox Abuse.ch | 2022-06-28 09:18:22 | 2022-06-28 09:18:22 | malicious-activity | |
| Phishing | Phishtank | 2017-10-15 08:39:04 | 2022-06-07 23:20:06 | compromised malicious-activity | |
| nymaim | Maltiverse Research Team | 2022-06-07 01:16:27 | 2022-06-07 01:16:27 | malicious-activity | |
| Malware Download | URLhaus Abuse.ch | 2022-05-16 15:15:23 | 2022-05-16 15:15:23 | malicious-activity | |
| virut | Maltiverse Research Team | 2018-11-15 02:17:15 | 2022-03-26 00:55:36 | malicious-activity | |
| Phishing | Maltiverse | 2021-02-27 00:44:20 | 2022-03-14 00:41:06 | compromised | |
| Malicious site | Hybrid-Analysis | 2018-07-16 04:30:19 | 2022-01-22 16:45:10 | ||
| Phishing site | Hybrid-Analysis | 2018-06-05 07:15:13 | 2022-01-10 03:00:21 | ||
| Phish.BTY | Hybrid-Analysis | 2021-10-04 03:00:25 | 2021-10-04 03:00:28 | ||
| Kryptik.ali2000016 | Hybrid-Analysis | 2021-08-04 13:31:18 | 2021-08-04 13:31:42 | ||
| Gen:Variant.Bulz | Hybrid-Analysis | 2021-08-04 13:17:41 | 2021-08-04 13:17:47 | ||
| Trojan.APosT | Hybrid-Analysis | 2021-07-31 11:00:05 | 2021-07-31 11:00:10 | ||
| Malware.Generic | Hybrid-Analysis | 2021-06-03 17:15:23 | 2021-07-06 06:00:21 | ||
| MSIL_Kryptik.EEX.gen | Hybrid-Analysis | 2021-06-30 01:00:16 | 2021-06-30 01:00:20 | ||
| VB:Trojan.VBA.Agent | Hybrid-Analysis | 2021-06-16 12:30:17 | 2021-06-16 12:30:20 | ||
| Malicious url | Cyber Threat Coalition | 2021-02-08 11:05:52 | 2021-05-03 01:18:53 | malicious-activity | |
| Social Engineering | Cyber Threat Coalition | 2021-02-15 08:06:47 | 2021-05-02 20:58:41 | malicious-activity | |
| Malware Download | Abuse.ch | 2019-03-20 06:27:34 | 2021-04-26 22:15:30 | malicious-activity | |
| Generic.Malware | Hybrid-Analysis | 2018-05-22 09:45:12 | 2021-04-19 17:00:31 | ||
| NetTool.TorTool | Hybrid-Analysis | 2021-04-01 08:03:34 | 2021-04-01 08:54:30 | ||
| FileRepMetagen [Malware] | Hybrid-Analysis | 2021-03-31 21:15:55 | 2021-03-31 22:06:53 | ||
| Malicious Hostname | Cyber Threat Coalition | 2021-02-08 10:43:40 | 2021-03-04 00:44:26 | malicious-activity | |
| Trickbot | Telefonica CO SOC | 2021-03-02 05:17:45 | 2021-03-03 02:17:44 | malicious-activity | S0266 TrickBot |
| Unwanted Software | Cyber Threat Coalition | 2021-02-28 09:05:31 | 2021-02-28 09:05:31 | malicious-activity | |
| Social Engineering | Maltiverse | 2021-02-27 00:44:20 | 2021-02-27 01:44:54 | malicious-activity | |
| HEUR:Trojan.Java.Agent | Hybrid-Analysis | 2021-02-22 22:30:19 | 2021-02-22 22:30:28 | ||
| WebInject | Cybercrime-tracker.net | 2021-02-08 11:29:15 | 2021-02-19 12:32:39 | malicious-activity | |
| Social Engineering | Phishtank | 2021-02-18 21:50:48 | 2021-02-18 21:50:48 | malicious-activity | |
| Agent | Hybrid-Analysis | 2020-01-31 10:45:20 | 2020-10-22 03:30:10 | ||
| apple phishing | Antiphishing.com.ar | 2020-02-09 01:40:05 | 2020-09-28 11:21:11 | ||
| Social Engineering | Antiphishing.com.ar | 2020-09-28 11:21:11 | 2020-09-28 11:21:11 | malicious-activity | |
| Unauthorized scanning of hosts | Blocklist.net.ua | 2020-08-20 04:05:35 | 2020-08-26 03:42:05 | ||
| uber phishing | Antiphishing.com.ar | 2020-08-05 11:06:29 | 2020-08-05 11:06:29 | ||
| Trojan.InstallCore | Hybrid-Analysis | 2020-07-16 10:15:27 | 2020-07-16 10:15:27 | ||
| Trojan.Generic | Hybrid-Analysis | 2019-12-05 08:00:11 | 2020-07-01 11:00:28 | ||
| Phishing Generic/Spear Phishing | OpenPhish | 2017-12-17 15:23:31 | 2020-06-26 04:39:12 | ||
| Social Engineering | OpenPhish | 2020-05-28 10:16:11 | 2020-06-26 04:39:12 | malicious-activity | |
| Hoax.JS.Phish | Hybrid-Analysis | 2020-06-18 21:15:15 | 2020-06-18 21:15:19 | ||
| paypal phishing | Antiphishing.com.ar | 2020-06-04 09:42:19 | 2020-06-04 09:42:19 | ||
| Phishing Office365 | OpenPhish | 2020-05-28 10:16:11 | 2020-05-28 10:16:11 | ||
| Threats200220200050 | CronUp Threat Intel | 2020-02-20 03:50:58 | 2020-02-20 03:50:58 | ||
| Kryptik.zcthd | Hybrid-Analysis | 2020-02-19 06:15:05 | 2020-02-19 06:15:07 | ||
| HEUR:Trojan.MSIL.Crypt | Hybrid-Analysis | 2020-01-17 16:18:49 | 2020-01-17 16:19:22 | ||
| Systweak.G potentially unwanted | Hybrid-Analysis | 2019-12-20 21:45:07 | 2019-12-20 21:45:07 | ||
| JS:Trojan.Cryxos | Hybrid-Analysis | 2019-11-30 05:15:06 | 2019-11-30 05:15:08 | ||
| DangerousObject.Multi | Hybrid-Analysis | 2019-10-15 18:00:09 | 2019-10-15 18:35:07 | ||
| Malicious url | Maltiverse Research Team | 2019-02-13 08:26:47 | 2019-10-15 03:27:07 | ||
| apt | Maltiverse Research Team | 2019-10-08 16:05:15 | 2019-10-08 16:05:15 | ||
| suppobox | Maltiverse Research Team | 2019-06-16 01:36:57 | 2019-06-16 01:36:57 | ||
| W97M.Downloader | Hybrid-Analysis | 2019-04-05 09:45:28 | 2019-04-05 10:30:05 | ||
| Pizd | Bambernek | 2019-03-23 07:00:43 | 2019-03-23 07:00:43 | ||
| ramnit | Maltiverse Research Team | 2019-03-12 08:20:06 | 2019-03-12 08:20:06 | ||
| Malicious Host | APT Notes | 2019-01-12 09:11:24 | 2019-01-12 09:11:24 | ||
| Anonymisation Services | IBM X-Force Exchange | 2013-04-17 13:30:00 | 2019-01-02 09:15:00 | ||
| Botnet Command and Control Server | IBM X-Force Exchange | 2013-07-15 01:10:00 | 2019-01-01 09:15:00 | ||
| Phishing ABSA Bank | Phishtank | 2018-12-02 17:23:29 | 2018-12-02 17:23:29 | ||
| Trojan.VBS.Downloader | Hybrid-Analysis | 2018-11-21 15:17:06 | 2018-11-21 15:17:06 | ||
| Phishing Facebook | Phishtank | 2017-10-15 18:00:47 | 2018-11-09 08:23:36 | ||
| Phishing Orange | Phishtank | 2018-11-06 09:45:37 | 2018-11-06 09:45:37 | ||
| Phishing Poste Italiane | Phishtank | 2018-10-09 08:47:13 | 2018-10-09 08:47:13 | ||
| Gen:Variant.Graftor | Hybrid-Analysis | 2018-10-08 11:15:09 | 2018-10-08 11:15:23 | ||
| banjori | Bambernek | 2017-11-10 11:26:11 | 2018-10-06 18:35:13 | ||
| Emotet | Telefonica CO SOC | 2018-10-06 09:31:25 | 2018-10-06 11:19:04 | S0367 Emotet | |
| Pykspa | Bambernek | 2018-09-27 06:48:26 | 2018-09-27 06:48:26 | ||
| Simda | Bambernek | 2018-06-07 06:56:55 | 2018-06-07 06:56:55 | ||
| Malware | IBM X-Force Exchange | 2013-03-29 03:31:00 | 2018-05-28 01:51:00 | ||
| Social Engineering | Google Safebrowsing | 2018-04-15 15:44:42 | 2018-05-14 16:53:34 | ||
| Phishing PayPal | Phishtank | 2018-04-15 16:00:19 | 2018-05-08 23:43:02 | ||
| National Police Agency JAPAN phishing | Maltiverse | 2018-04-16 09:53:21 | 2018-04-16 09:53:21 | ||
| Phishing Banco De Brasil | Phishtank | 2018-04-15 16:49:27 | 2018-04-15 16:49:27 | ||
| Phishing AT&T | Phishtank | 2018-04-15 15:58:33 | 2018-04-15 15:58:33 | ||
| virut | Maltiverse | 2018-04-02 11:27:26 | 2018-04-02 11:27:26 | ||
| ramnit | Maltiverse | 2018-03-31 01:30:24 | 2018-03-31 01:30:24 | ||
| Ramnit | Bambernek | 2018-03-16 11:55:26 | 2018-03-16 11:55:26 | ||
| Tesla | Cybercrime-tracker.net | 2018-02-27 13:55:18 | 2018-02-27 13:55:18 | ||
| Nymaim | Bambernek | 2018-02-12 11:28:54 | 2018-02-12 11:28:54 | ||
| Defacement | Zone-H | 2017-12-11 11:01:26 | 2017-12-11 11:01:26 | ||
| Malicious host | IBM X-Force Exchange | 2017-12-10 17:39:02 | 2017-12-10 17:39:02 | ||
| backdoor,ransomware,svg | Maltiverse | 2017-12-02 19:29:40 | 2017-12-02 19:29:40 | ||
| backdoor,plugx | Maltiverse | 2017-11-22 22:00:34 | 2017-11-22 22:00:34 | ||
| ET CNC Ransomware Tracker Reported CnC Server TCP | Emerging Threats | 2017-10-17 11:30:06 | 2017-10-19 11:18:41 | ||
| ET CNC Ransomware Tracker Reported CnC Server UDP | Emerging Threats | 2017-10-15 14:05:13 | 2017-10-19 11:18:41 | ||
| Phishing Microsoft | Phishtank | 2017-10-15 17:47:27 | 2017-10-15 17:47:27 | ||
| Ransomware Locky distribution site | Ransomware Tracker | 2017-10-15 17:03:17 | 2017-10-15 17:03:17 | ||
| Phishing LinkedIn | Phishtank | 2017-10-15 16:49:45 | 2017-10-15 16:49:45 | ||
| Phishing AOL | Phishtank | 2017-10-15 16:44:20 | 2017-10-15 16:44:20 | ||
| Ransomware | Ransomware Tracker | 2017-10-15 16:40:27 | 2017-10-15 16:40:27 | ||
| Phishing Dropbox | Phishtank | 2017-10-15 16:27:05 | 2017-10-15 16:27:05 | ||
| Phishing Google | Phishtank | 2017-10-15 16:24:11 | 2017-10-15 16:24:11 | ||
| ZeuS | Cybercrime-tracker.net | 2017-10-15 16:00:20 | 2017-10-15 16:00:20 | ||
| Inmortal malware domain | Malware Domains | 2017-10-15 14:46:21 | 2017-10-15 14:46:21 | ||
| Kronos | Cybercrime-tracker.net | 2017-10-15 14:22:29 | 2017-10-15 14:22:29 | ||
| Pony | Cybercrime-tracker.net | 2017-10-15 14:00:16 | 2017-10-15 14:00:16 | S0453 Pony | |
| Vawtrak | Bambernek | 2017-10-15 13:11:55 | 2017-10-15 13:11:55 | ||
| Suppobox | Bambernek | 2017-10-15 13:11:26 | 2017-10-15 13:11:26 | ||
| Spamming | Alienvault Ip Reputation Database | 2017-10-15 09:28:32 | 2017-10-15 09:28:32 | ||
| Phishing DHL | Phishtank | 2017-10-15 08:37:49 | 2017-10-15 08:37:49 |
Tags
raccoon recordbreaker stealer mohazo raccoonstealer racealer racoon phishing c&c c2 dga malware_download malware nymaim ramnit simda pykspa emotet banker compromised payload delivery banjori https://www.threatminer.org/report.php?q=appendix-theurpageconnectiontobahamutconfuciusandpatchwork.pdf&y=2018 doc pizd apt sector:online services office365 generic/spear phishing abuse sload tickbot dridexWhois information
- AS name
- AS23005 SWITCH, LTD
- AS registry
- arin
- AS date
- 2000-08-23 00:00:00
- AS CIDR
- 209.99.0.0/17
- CIDR
- 209.99.0.0/17
- Registrant
- SWITCH, LTD
- Address
- 7135 South Decatur Blvd
- City
- Houston
- State
- TX
- Postal code
- 77080
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected]
- First indexed
- 2017-10-15 08:37:49
- Last updated
- 2026-07-24 17:16:17