45.137.22.123

Classification: Neutral

45.137.22.123 is a neutral IP address. Reported by 6 threat sources, last seen 2025-03-24. Network: AS51447 Rootlayer Web Services Ltd..

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Agent Tesla Maltrail 2025-02-25 16:37:07 2025-03-24 11:35:23 malicious-activity S0331 Agent Tesla
RedLine Stealer ThreatFox Abuse.ch 2024-09-29 11:17:04 2024-10-01 10:20:13 malicious-activity
Ave Maria ThreatFox Abuse.ch 2023-09-26 11:18:11 2023-09-28 10:54:10 malicious-activity
Mail Spammer Blocklist.de 2022-02-05 03:55:09 2023-08-09 03:28:42 malicious-activity
IMAP Attacker Blocklist.de 2022-02-05 03:42:01 2023-08-09 03:21:53 malicious-activity
Brute force attack on the SMTP service of the server S2 Blocklist.net.ua 2022-07-26 02:26:38 2022-07-26 02:26:38 malicious-activity
Generic.Malware Hybrid-Analysis 2020-12-02 16:00:24 2020-12-02 16:00:24
Mail Spammer Barracuda 2020-12-02 16:00:24 2020-12-02 16:00:24

Tags

avemariarat c2 historicalandnew warzonerat port:5200 ave_maria warzone rat avemaria mail spam attacker imap pop3 sasl bot abuse redlinestealer port:55615 recordstealer port:65

Whois information

AS name
AS51447 Rootlayer Web Services Ltd.
AS registry
ripencc
AS date
2019-08-05 00:00:00
AS CIDR
45.137.22.0/24
CIDR
45.137.20.0/22
Registrant
Rootlayer Web Services Ltd.
Address
134/7 B, Furfura Sharif Road, Darus Salam, Mirpur, Dhaka 1216 Dhaka BANGLADESH
City
Naaldwijk
Postal code
2671 JA
Country
NL — Netherlands 🇳🇱
First indexed
2020-12-02 16:00:24
Last updated
2025-03-24 11:43:53

Malicious IPs in the same CIDR

45.137.22.253 45.137.22.166