3.129.187.220

Classification: Suspicious

3.129.187.220 is a suspicious IP address. Linked to Njrat, Asyncrat malware. Reported by 3 threat sources, last seen 2025-03-27.

MITRE ATT&CK associations

Malware families: NJRAT (S0385) ASYNCRAT (S1087)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Asyncrat Maltrail 2025-03-27 13:25:13 2025-03-27 13:25:13 malicious-activity S1087 AsyncRAT
NjRAT ThreatFox Abuse.ch 2021-10-27 00:06:20 2023-11-13 16:18:22 malicious-activity S0385 njRAT
RedLine Stealer ThreatFox Abuse.ch 2022-07-18 18:18:44 2023-06-09 22:17:47 malicious-activity
Nanocore RAT ThreatFox Abuse.ch 2022-07-20 23:18:48 2023-06-04 00:18:23 malicious-activity
IL:Trojan.MSILZilla Hybrid-Analysis 2021-09-09 23:15:34 2022-01-24 21:45:51
Malware Hybrid-Analysis 2021-08-04 17:15:22 2021-12-21 17:16:00
Backdoor.Bladabindi Hybrid-Analysis 2021-12-20 03:46:12 2021-12-20 03:46:12
Generic.MSIL.Bladabindi Hybrid-Analysis 2021-09-13 15:00:43 2021-09-13 15:00:43
Trojan.Bladabindi Hybrid-Analysis 2021-07-27 21:45:11 2021-07-27 21:45:11
Gen:Variant.Semper.DotNet Hybrid-Analysis 2021-07-13 21:45:29 2021-07-13 21:45:29
Generic.Malware Hybrid-Analysis 2020-10-28 22:15:20 2021-04-28 22:00:49
Malware.Heuristic Hybrid-Analysis 2021-03-01 19:45:55 2021-03-01 19:45:55
Gen:Variant.Razy Hybrid-Analysis 2020-12-01 17:00:39 2020-12-01 17:00:39
MSIL_Bladabindi.A.gen Hybrid-Analysis 2020-11-27 20:15:15 2020-11-27 20:15:15
CIL.HeapOverride Hybrid-Analysis 2020-10-29 15:45:15 2020-10-29 15:45:15

Tags

njrat port:12181 bladabindi lime-worm port:18816 port:17683 redlinestealer port:17721 nanocore rat port:17403 nancrat port:10918 port:11272 port:15925 port:16280 port:18766 port:13705 port:11044 port:12496 port:17755 port:14880 port:17811 port:19235 port:16559 port:12759 port:19155 port:11248 port:11113 port:12170 port:15518 port:13571 port:11654 port:11271 port:16574 port:19454 port:16142 port:19367 port:8808

Whois information

AS name
AS16509 Amazon Technologies Inc.
AS registry
arin
AS date
2018-06-25 00:00:00
AS CIDR
3.128.0.0/15
CIDR
3.128.0.0/9
Registrant
Amazon Technologies Inc.
Address
410 Terry Ave N.
City
Columbus
State
OH
Postal code
43216
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected], [email protected], [email protected]
First indexed
2020-10-28 22:15:20
Last updated
2026-04-09 12:20:05

Malicious IPs in the same CIDR

3.128.90.105 3.128.255.117