31.171.130.31

Classification: Malicious

31.171.130.31 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-11. Network: AS206092 NR CUST EXPRESSVPN.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Empty reason Blocklist.net.ua 2026-09-04 16:07:48 2026-09-11 16:05:58 attacker malicious-activity
DDoS Attacker Blocklist.net.ua 2026-08-02 16:00:20 2026-09-10 16:06:17 attacker malicious-activity
HTTP Attacker Blocklist.de 2026-07-28 07:00:27 2026-07-28 07:00:27 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-12-27 01:13:41 2026-06-03 18:49:12 anomalous-activity
Malicious Host AbuseIPDB 2025-06-20 20:10:24 2026-03-24 02:05:36 malicious-activity
HTTP Spammer StopForumSpam.com 2025-02-19 21:46:09 2025-09-13 16:25:57 malicious-activity
VPN IPWhois.io 2025-06-05 05:32:45 2025-06-16 05:08:40 anonymization
Proxy IPWhois.io 2024-12-27 05:56:07 2025-04-02 06:25:23 anonymization

Tags

bot abuse apache ddos rfi attacker

Whois information

AS name
AS206092 NR CUST EXPRESSVPN
AS registry
ripencc
AS date
2011-03-31 00:00:00
AS CIDR
31.171.130.0/24
Registrant
NR CUST EXPRESSVPN
City
London
Postal code
SW1
Country
GB — United Kingdom 🇬🇧
First indexed
2024-12-27 05:56:06
Last updated
2026-09-11 16:05:58

Malicious IPs in the same CIDR

31.171.130.122 31.171.130.138 31.171.130.143 31.171.130.147 31.171.130.156 31.171.130.162 31.171.130.120 31.171.130.144 31.171.130.150 31.171.130.164 31.171.130.139 31.171.130.140 31.171.130.146 31.171.130.151 31.171.130.157 31.171.130.133 31.171.130.136 31.171.130.148 31.171.130.152 31.171.130.163 31.171.130.79 31.171.130.82 31.171.130.91 31.171.130.103 31.171.130.104