31.41.44.109

Classification: Malicious

31.41.44.109 is a malicious IP address. Linked to Socgholish malware. Reported by 2 threat sources, last seen 2026-09-03. Network: AS56577 Relink LTD.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: SOCGHOLISH (S1124)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2023-01-10 14:17:44 2026-09-03 02:57:04 attacker malicious-activity
FAKEUPDATES ThreatFox Abuse.ch 2024-04-22 13:19:18 2024-04-24 12:21:23 malicious-activity S1124 SocGholish
ISFB ThreatFox Abuse.ch 2023-01-10 14:17:43 2023-01-12 13:18:28 malicious-activity

Tags

geo gozi isfb ita ursnif port:445 gozi isfb iap pandemyia keitarotds socgholish port:443 fakeupdate

Whois information

AS name
AS56577 Relink LTD
AS registry
ripencc
AS date
2011-02-18 00:00:00
AS CIDR
31.41.40.0/21
CIDR
31.41.40.0/21
Registrant
Relink LTD
Address
Sokolnicheskaya sq.,4A 107113 Moscow RUSSIAN FEDERATION
City
Moscow
Postal code
109012
Country
RU — Russian Federation 🇷🇺
Contact email
[email protected], [email protected]
First indexed
2023-01-10 14:17:43
Last updated
2026-09-03 02:57:07

Malicious IPs in the same CIDR

31.41.44.109 31.41.44.97