3.138.180.119
Classification: Neutral
3.138.180.119 is a neutral IP address. Reported by 3 threat sources, last seen 2025-06-13. Network: AS16509 Amazon Technologies Inc..
MITRE ATT&CK associations
Malware families: ASYNCRAT (S1087) NJRAT (S0385)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| NjRAT | ThreatFox Abuse.ch | 2021-10-27 00:06:20 | 2025-06-13 19:19:46 | malicious-activity | S0385 njRAT |
| Asyncrat | Maltrail | 2025-03-27 13:35:37 | 2025-03-27 13:35:37 | malicious-activity | S1087 AsyncRAT |
| Nanocore RAT | ThreatFox Abuse.ch | 2022-07-20 11:18:27 | 2024-02-10 11:19:39 | malicious-activity | |
| Meterpreter | ThreatFox Abuse.ch | 2023-10-02 09:22:21 | 2023-10-04 08:21:53 | malicious-activity | |
| RedLine Stealer | ThreatFox Abuse.ch | 2023-06-07 21:17:03 | 2023-06-09 20:18:00 | malicious-activity | |
| Revenge RAT | ThreatFox Abuse.ch | 2022-03-24 00:03:59 | 2022-03-24 00:03:59 | malicious-activity | |
| Backdoor.MSIL.BLADABINDI | Hybrid-Analysis | 2021-12-27 18:00:10 | 2021-12-27 18:00:10 | ||
| AsyncRAT | ThreatFox Abuse.ch | 2021-12-05 00:04:47 | 2021-12-06 00:07:09 | malicious-activity | |
| Malware | Hybrid-Analysis | 2021-10-22 00:00:10 | 2021-10-22 00:00:10 | ||
| IL:Trojan.MSILZilla | Hybrid-Analysis | 2021-09-09 23:15:34 | 2021-09-09 23:15:34 | ||
| Trojan.Bladabindi | Hybrid-Analysis | 2021-07-27 21:45:11 | 2021-07-27 21:45:11 | ||
| Gen:Variant.Semper.DotNet | Hybrid-Analysis | 2021-07-13 21:45:28 | 2021-07-13 21:45:28 | ||
| Generic.Malware | Hybrid-Analysis | 2020-10-28 22:15:20 | 2021-04-28 22:00:49 | ||
| Exploit.HTML | Hybrid-Analysis | 2021-01-12 15:45:22 | 2021-01-12 15:45:22 |
Tags
c2 historicalandnew meterpreter port:18712 njrat port:18816 bladabindi lime-worm redlinestealer port:14019 nanocore rat port:17403 nancrat port:10918 port:15925 port:16280 port:13961 port:18766 port:12919 port:11044 port:17755 port:14880 port:16292 port:13648 port:19235 port:12362 port:17811 port:12759 port:19155 port:11248 port:13568 port:11113 port:12170 revengerat port:16025 revetrat port:15518 port:15789 port:14567 port:11298 asyncrat port:18729 port:11654 port:14032 port:11271 port:19454 port:12516 port:16142 port:19367 port:16825 port:19869Whois information
- AS name
- AS16509 Amazon Technologies Inc.
- AS registry
- arin
- AS date
- 2018-06-25 00:00:00
- AS CIDR
- 3.136.0.0/13
- CIDR
- 3.128.0.0/9
- Registrant
- Amazon Technologies Inc.
- Address
- 410 Terry Ave N.
- City
- Dublin
- State
- OH
- Postal code
- 43017
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2020-10-28 22:15:20
- Last updated
- 2025-06-13 19:19:48
Malicious IPs in the same CIDR
3.142.211.80 3.142.255.184 3.137.167.53 3.141.210.37 3.137.123.231 3.142.105.213 3.141.177.1 3.136.236.200 3.136.25.207 3.140.182.107 3.136.160.1