31.171.130.31
Classification: Malicious
31.171.130.31 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-11. Network: AS206092 NR CUST EXPRESSVPN.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Empty reason | Blocklist.net.ua | 2026-09-04 16:07:48 | 2026-09-11 16:05:58 | attacker malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2026-08-02 16:00:20 | 2026-09-10 16:06:17 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-07-28 07:00:27 | 2026-07-28 07:00:27 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-12-27 01:13:41 | 2026-06-03 18:49:12 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2025-06-20 20:10:24 | 2026-03-24 02:05:36 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2025-02-19 21:46:09 | 2025-09-13 16:25:57 | malicious-activity | |
| VPN | IPWhois.io | 2025-06-05 05:32:45 | 2025-06-16 05:08:40 | anonymization | |
| Proxy | IPWhois.io | 2024-12-27 05:56:07 | 2025-04-02 06:25:23 | anonymization |
Tags
bot abuse apache ddos rfi attackerWhois information
- AS name
- AS206092 NR CUST EXPRESSVPN
- AS registry
- ripencc
- AS date
- 2011-03-31 00:00:00
- AS CIDR
- 31.171.130.0/24
- Registrant
- NR CUST EXPRESSVPN
- City
- London
- Postal code
- SW1
- Country
- GB — United Kingdom 🇬🇧
- First indexed
- 2024-12-27 05:56:06
- Last updated
- 2026-09-11 16:05:58
Malicious IPs in the same CIDR
31.171.130.122 31.171.130.138 31.171.130.143 31.171.130.147 31.171.130.156 31.171.130.162 31.171.130.120 31.171.130.144 31.171.130.150 31.171.130.164 31.171.130.139 31.171.130.140 31.171.130.146 31.171.130.151 31.171.130.157 31.171.130.133 31.171.130.136 31.171.130.148 31.171.130.152 31.171.130.163 31.171.130.79 31.171.130.82 31.171.130.91 31.171.130.103 31.171.130.104