4.213.56.161

Classification: Malicious

4.213.56.161 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-10. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-01-01 14:01:30 2026-09-10 16:01:32 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:02:30 2026-09-04 16:02:30 attacker malicious-activity
Suspicious Host AbuseIPDB 2026-03-05 12:42:30 2026-03-05 12:42:30 anomalous-activity
Malicious Host AbuseIPDB 2025-12-28 19:28:55 2026-02-15 03:33:04 compromised malicious-activity
Bruteforce login attacker Blocklist.de 2025-12-29 19:23:43 2025-12-29 19:23:43 malicious-activity
HTTP bot Blocklist.de 2025-12-29 11:40:20 2025-12-29 11:40:20 malicious-activity
HTTP Attacker Blocklist.de 2025-12-29 11:08:46 2025-12-29 11:08:46 malicious-activity
HTTP Attacker AbuseIPDB 2025-12-28 19:25:17 2025-12-29 10:44:22 malicious-activity
Hacking AbuseIPDB 2025-12-28 19:26:49 2025-12-29 10:15:02 malicious-activity
SSH Attacker AbuseIPDB 2025-12-28 19:29:36 2025-12-29 10:09:32 malicious-activity
Bruteforce AbuseIPDB 2025-12-28 19:26:05 2025-12-29 10:09:32 malicious-activity
Port Scanner AbuseIPDB 2025-12-28 19:47:04 2025-12-29 09:45:38 anomalous-activity
HTTP Scrapper AbuseIPDB 2025-12-28 19:26:05 2025-12-29 09:43:09 anomalous-activity
DDoS Attacker AbuseIPDB 2025-12-28 20:14:12 2025-12-29 09:10:10 malicious-activity
Phishing AbuseIPDB 2025-12-28 22:36:45 2025-12-29 08:23:51 malicious-activity
SQL Injection AbuseIPDB 2025-12-28 19:49:32 2025-12-29 07:57:18 malicious-activity
Known Attacker AbuseIPDB 2025-12-28 22:36:45 2025-12-28 22:36:45 malicious-activity
Mail Spammer AbuseIPDB 2025-12-28 22:36:45 2025-12-28 22:36:45 malicious-activity
FTP Attacker AbuseIPDB 2025-12-28 19:30:12 2025-12-28 22:36:45 malicious-activity
Proxy AbuseIPDB 2025-12-28 19:30:12 2025-12-28 19:30:12 anonymization

Tags

apache ddos rfi attacker spam bruteforce bot login joomla wordpress abuse

Whois information

AS name
AS8075 Microsoft Corporation
Registrant
Microsoft Corporation
City
Pune
Postal code
411002
Country
IN — India 🇮🇳
First indexed
2025-12-29 10:50:02
Last updated
2026-09-10 16:01:32