4.213.56.161
Classification: Malicious
4.213.56.161 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-10. Network: AS8075 Microsoft Corporation.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Open proxy — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| DDoS Attacker | Blocklist.net.ua | 2026-01-01 14:01:30 | 2026-09-10 16:01:32 | attacker malicious-activity | |
| Empty reason | Blocklist.net.ua | 2026-09-04 16:02:30 | 2026-09-04 16:02:30 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2026-03-05 12:42:30 | 2026-03-05 12:42:30 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2025-12-28 19:28:55 | 2026-02-15 03:33:04 | compromised malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2025-12-29 19:23:43 | 2025-12-29 19:23:43 | malicious-activity | |
| HTTP bot | Blocklist.de | 2025-12-29 11:40:20 | 2025-12-29 11:40:20 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2025-12-29 11:08:46 | 2025-12-29 11:08:46 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-12-28 19:25:17 | 2025-12-29 10:44:22 | malicious-activity | |
| Hacking | AbuseIPDB | 2025-12-28 19:26:49 | 2025-12-29 10:15:02 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2025-12-28 19:29:36 | 2025-12-29 10:09:32 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2025-12-28 19:26:05 | 2025-12-29 10:09:32 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2025-12-28 19:47:04 | 2025-12-29 09:45:38 | anomalous-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-12-28 19:26:05 | 2025-12-29 09:43:09 | anomalous-activity | |
| DDoS Attacker | AbuseIPDB | 2025-12-28 20:14:12 | 2025-12-29 09:10:10 | malicious-activity | |
| Phishing | AbuseIPDB | 2025-12-28 22:36:45 | 2025-12-29 08:23:51 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2025-12-28 19:49:32 | 2025-12-29 07:57:18 | malicious-activity | |
| Known Attacker | AbuseIPDB | 2025-12-28 22:36:45 | 2025-12-28 22:36:45 | malicious-activity | |
| Mail Spammer | AbuseIPDB | 2025-12-28 22:36:45 | 2025-12-28 22:36:45 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2025-12-28 19:30:12 | 2025-12-28 22:36:45 | malicious-activity | |
| Proxy | AbuseIPDB | 2025-12-28 19:30:12 | 2025-12-28 19:30:12 | anonymization |
Tags
apache ddos rfi attacker spam bruteforce bot login joomla wordpress abuseWhois information
- AS name
- AS8075 Microsoft Corporation
- Registrant
- Microsoft Corporation
- City
- Pune
- Postal code
- 411002
- Country
- IN — India 🇮🇳
- First indexed
- 2025-12-29 10:50:02
- Last updated
- 2026-09-10 16:01:32