3.129.187.220
Classification: Suspicious
3.129.187.220 is a suspicious IP address. Linked to Njrat, Asyncrat malware. Reported by 3 threat sources, last seen 2025-03-27.
MITRE ATT&CK associations
Malware families: NJRAT (S0385) ASYNCRAT (S1087)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Asyncrat | Maltrail | 2025-03-27 13:25:13 | 2025-03-27 13:25:13 | malicious-activity | S1087 AsyncRAT |
| NjRAT | ThreatFox Abuse.ch | 2021-10-27 00:06:20 | 2023-11-13 16:18:22 | malicious-activity | S0385 njRAT |
| RedLine Stealer | ThreatFox Abuse.ch | 2022-07-18 18:18:44 | 2023-06-09 22:17:47 | malicious-activity | |
| Nanocore RAT | ThreatFox Abuse.ch | 2022-07-20 23:18:48 | 2023-06-04 00:18:23 | malicious-activity | |
| IL:Trojan.MSILZilla | Hybrid-Analysis | 2021-09-09 23:15:34 | 2022-01-24 21:45:51 | ||
| Malware | Hybrid-Analysis | 2021-08-04 17:15:22 | 2021-12-21 17:16:00 | ||
| Backdoor.Bladabindi | Hybrid-Analysis | 2021-12-20 03:46:12 | 2021-12-20 03:46:12 | ||
| Generic.MSIL.Bladabindi | Hybrid-Analysis | 2021-09-13 15:00:43 | 2021-09-13 15:00:43 | ||
| Trojan.Bladabindi | Hybrid-Analysis | 2021-07-27 21:45:11 | 2021-07-27 21:45:11 | ||
| Gen:Variant.Semper.DotNet | Hybrid-Analysis | 2021-07-13 21:45:29 | 2021-07-13 21:45:29 | ||
| Generic.Malware | Hybrid-Analysis | 2020-10-28 22:15:20 | 2021-04-28 22:00:49 | ||
| Malware.Heuristic | Hybrid-Analysis | 2021-03-01 19:45:55 | 2021-03-01 19:45:55 | ||
| Gen:Variant.Razy | Hybrid-Analysis | 2020-12-01 17:00:39 | 2020-12-01 17:00:39 | ||
| MSIL_Bladabindi.A.gen | Hybrid-Analysis | 2020-11-27 20:15:15 | 2020-11-27 20:15:15 | ||
| CIL.HeapOverride | Hybrid-Analysis | 2020-10-29 15:45:15 | 2020-10-29 15:45:15 |
Tags
njrat port:12181 bladabindi lime-worm port:18816 port:17683 redlinestealer port:17721 nanocore rat port:17403 nancrat port:10918 port:11272 port:15925 port:16280 port:18766 port:13705 port:11044 port:12496 port:17755 port:14880 port:17811 port:19235 port:16559 port:12759 port:19155 port:11248 port:11113 port:12170 port:15518 port:13571 port:11654 port:11271 port:16574 port:19454 port:16142 port:19367 port:8808Whois information
- AS name
- AS16509 Amazon Technologies Inc.
- AS registry
- arin
- AS date
- 2018-06-25 00:00:00
- AS CIDR
- 3.128.0.0/15
- CIDR
- 3.128.0.0/9
- Registrant
- Amazon Technologies Inc.
- Address
- 410 Terry Ave N.
- City
- Columbus
- State
- OH
- Postal code
- 43216
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2020-10-28 22:15:20
- Last updated
- 2026-04-09 12:20:05