3.69.157.220
Classification: Suspicious
3.69.157.220 is a suspicious IP address. Linked to Asyncrat, Nanocore malware. Reported by 4 threat sources, last seen 2025-09-01.
MITRE ATT&CK associations
Malware families: ASYNCRAT (S1087) NANOCORE (S0336) DCRAT (S9017) NJRAT (S0385)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| NjRAT | ThreatFox Abuse.ch | 2022-05-20 05:32:36 | 2025-09-01 22:20:56 | malicious-activity | S0385 njRAT |
| XWorm | ThreatFox Abuse.ch | 2025-08-30 10:10:59 | 2025-09-01 10:19:22 | malicious-activity | |
| DCRat | ThreatFox Abuse.ch | 2025-06-16 09:18:15 | 2025-06-18 07:20:05 | malicious-activity | S9017 DCRAT |
| Asyncrat | Maltrail | 2025-03-27 13:35:41 | 2025-03-27 13:47:48 | malicious-activity | S1087 AsyncRAT |
| Nanocore RAT | ThreatFox Abuse.ch | 2024-07-31 17:17:07 | 2024-08-02 16:20:36 | malicious-activity | S0336 NanoCore |
| Malicious URL | Hybrid-Analysis | 2024-02-01 10:45:04 | 2024-02-01 10:45:04 | ||
| Meterpreter | ThreatFox Abuse.ch | 2023-10-02 09:22:51 | 2023-10-04 08:22:21 | malicious-activity | |
| AsyncRAT | ThreatFox Abuse.ch | 2022-10-21 11:19:16 | 2023-09-12 21:28:01 | malicious-activity | S1087 AsyncRAT |
| Proxy | FireHOL | 2023-04-08 13:15:04 | 2023-05-28 12:29:19 | anonymization | |
| Malware | Hybrid-Analysis | 2021-10-10 23:30:20 | 2021-10-10 23:30:20 |
Tags
c2 historicalandnew meterpreter port:14676 njrat port:15392 bladabindi lime-worm asyncrat mightcontainvariantsofasyncrat port:10147 port:4824 port:16193 port:15925 port:13480 port:13034 port:16370 port:10784 port:12660 port:15224 anonymization port:17674 port:18168 port:14453 port:19905 port:16424 port:12582 port:17297 port:14000 port:12420 port:18736 port:10146 port:13090 port:10945 port:13730 port:18280 port:11553 port:10224 port:18644 port:17882 port:16320 rat port:12104 port:18313 port:16211 port:13992 port:14104 port:12180 port:10384 port:11713 port:13458 port:10922 port:11498 port:14456 port:12147 port:19220 port:11952 port:13003 port:10298 port:14402 port:15520 port:10673 port:11080 port:17155 port:12765 port:12125 port:14744 port:13672 port:12377 port:11964 port:13006 port:15748 port:18942 nanocore port:13201 nancrat port:11237 port:12482 port:8808 port:13372 amazon-02 censys dcrat as16509 darkcrystal rat port:17831 port:15537 port:18211 xworm port:14147Whois information
- AS name
- AS16509 A100 ROW GmbH
- AS registry
- arin
- AS date
- 2017-12-20 00:00:00
- AS CIDR
- 3.64.0.0/12
- CIDR
- 3.0.0.0/9
- Registrant
- A100 ROW GmbH
- Address
- 410 Terry Ave N.
- City
- Frankfurt am Main
- State
- WA
- Postal code
- 60313
- Country
- DE — Germany 🇩🇪
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2021-10-10 23:30:20
- Last updated
- 2026-08-03 12:00:01
Malicious IPs in the same CIDR
3.64.4.198 3.70.164.132 3.70.45.136 3.69.115.178 3.68.171.119 3.71.146.175 3.65.196.126 3.73.120.104 3.65.193.237 3.75.145.52 3.67.62.142 3.72.79.211