31.185.104.19
Classification: Suspicious
31.185.104.19 is a suspicious IP address. Linked to Tor malware. Reported by 17 threat sources, last seen 2026-09-02.
Current activity
- Open proxy — Provides anonymization that can hide an attacker.
MITRE ATT&CK associations
Malware families: TOR (S0183)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Proxy | FireHOL | 2021-12-22 11:57:57 | 2026-09-02 18:21:18 | anomalous-activity anonymization proxy | |
| Anonymizer | FireHOL | 2026-02-27 08:18:31 | 2026-09-02 17:24:58 | anomalous-activity anonymization | |
| Proxy | IPWhois.io | 2025-02-16 21:10:08 | 2026-08-07 16:51:15 | anonymization proxy | |
| Anonymizer | FireHol | 2022-01-18 10:36:24 | 2022-12-29 14:38:21 | anonymization | |
| Anonymizer | Maltiverse Research Team | 2020-11-21 14:14:37 | 2021-12-21 04:40:47 | anonymization anonymizer | |
| HTTP Attacker | CruzIT | 2018-06-21 06:30:59 | 2021-12-07 05:39:14 | malicious-activity | |
| Malware | Hybrid-Analysis | 2021-07-15 22:15:07 | 2021-11-18 15:01:46 | ||
| AIT:Trojan.Nymeria | Hybrid-Analysis | 2021-06-23 23:01:06 | 2021-06-23 23:01:06 | ||
| ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic | Emerging Threats | 2018-06-23 07:28:43 | 2020-09-30 11:49:29 | anonymization | |
| ET TOR Known Tor Exit Node TCP Traffic | Emerging Threats | 2018-07-10 07:31:26 | 2020-09-30 11:47:53 | anonymization | |
| Proxy | Mr.Looquer | 2020-09-08 12:29:38 | 2020-09-08 12:29:38 | ||
| SSH Attacker | Blocklist.net.ua | 2018-06-16 08:13:54 | 2020-08-21 07:57:24 | ||
| Malicious Host | HoneyDB | 2019-07-14 00:00:00 | 2020-08-09 00:00:00 | ||
| DDoS attack | Blocklist.net.ua | 2019-11-30 00:52:24 | 2020-07-06 08:59:14 | ||
| SSH Attacker | Telefonica CO SOC | 2018-11-25 02:58:04 | 2020-07-01 09:58:13 | ||
| TOR Exit Node | TorProject.org | 2019-11-03 13:26:40 | 2020-04-22 16:38:49 | anonymizer | |
| Generic.Malware | Hybrid-Analysis | 2020-04-04 18:00:06 | 2020-04-04 18:00:06 | ||
| ET COMPROMISED Known Compromised or Hostile Host Traffic UDP | Emerging Threats | 2019-07-09 01:59:19 | 2019-09-27 08:11:20 | ||
| ET COMPROMISED Known Compromised or Hostile Host Traffic TCP | Emerging Threats | 2019-07-10 01:51:02 | 2019-09-27 01:39:21 | ||
| HTTP Spammer | Cleantalk.org | 2018-06-30 07:02:01 | 2019-09-10 07:35:32 | ||
| Malicious host | Darklist | 2019-08-18 01:09:30 | 2019-08-18 01:09:30 | ||
| Tor | Hybrid-Analysis | 2019-03-22 14:01:56 | 2019-03-22 14:01:56 | S0183 Tor | |
| Parasite traffic on site test-drives.autopark.in.ua. | Blocklist.net.ua | 2018-10-14 06:44:03 | 2019-02-17 07:22:33 | ||
| HTTP Spammer | IP Blacklist Cloud | 2019-02-14 08:27:59 | 2019-02-14 08:27:59 | ||
| Parasite traffic on site news.autopark.in.ua. | Blocklist.net.ua | 2018-10-27 06:43:50 | 2018-10-27 06:43:50 | ||
| Parasite traffic on site mkarapuz.com.ru. | Blocklist.net.ua | 2018-09-12 07:02:27 | 2018-09-12 07:02:27 | ||
| ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic | Emerging Threats | 2018-06-20 22:15:57 | 2018-08-29 07:36:51 | ||
| ET TOR Known Tor Exit Node UDP Traffic | Emerging Threats | 2018-06-20 22:15:27 | 2018-08-29 07:36:21 | ||
| HTTP Attacker | BadIPs | 2018-07-14 06:56:21 | 2018-07-17 06:38:50 | ||
| HTTP Spammer | Myip.ms | 2018-02-09 21:18:02 | 2018-02-09 21:18:02 |
Tags
anonymization anonymizer abuse bot tor compromised attacker ddos apache noscript ssh bruteforceWhois information
- AS name
- AS43847 Martin Prager Trading AS Nbiserv
- AS registry
- ripencc
- AS date
- 2011-03-16 00:00:00
- AS CIDR
- 31.185.104.0/21
- Registrant
- Martin Prager Trading AS Nbiserv
- City
- Bethenhausen
- Postal code
- 07554
- Country
- DE — Germany 🇩🇪
- First indexed
- 2018-02-09 21:18:02
- Last updated
- 2026-09-02 18:21:18