45.9.148.138

Classification: Malicious

45.9.148.138 is a malicious IP address. Reported by 9 threat sources, last seen 2026-08-18. Network: AS49447 Nice IT Customers Network.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Proxy IPWhois.io 2025-02-17 11:44:59 2026-08-18 12:39:16 anonymization proxy
Mail Spammer Barracuda 2022-08-20 03:30:12 2026-08-18 12:39:16 attacker malicious-activity
Anonymizer FireHOL 2026-05-23 09:50:53 2026-08-04 20:24:50 anomalous-activity anonymization
Proxy FireHOL 2022-12-31 18:45:36 2026-08-02 21:58:11 anomalous-activity anonymization proxy
Meterpreter ThreatFox Abuse.ch 2023-10-02 09:20:46 2023-10-02 09:20:46 malicious-activity
Anonymizer FireHol 2022-12-29 07:17:34 2022-12-29 18:39:43 anonymization
HTTP Spammer StopForumSpam.com 2022-08-22 04:02:17 2022-11-30 01:21:39 malicious-activity
ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic Emerging Threats 2022-08-20 03:22:38 2022-09-11 03:02:19 anonymization
ET TOR Known Tor Exit Node TCP Traffic Emerging Threats 2022-08-20 03:20:49 2022-09-11 03:00:35 anonymization
HTTP Spammer Sblam 2022-08-25 02:55:30 2022-09-09 03:05:18 malicious-activity
SSH Attacker Blocklist.de 2022-08-24 02:12:52 2022-09-03 02:22:55 malicious-activity

Tags

c2 historicalandnew meterpreter anonymization bot abuse tor ssh bruteforce

Whois information

AS name
AS49447 Nice IT Customers Network
AS registry
ripencc
AS date
2019-04-18 00:00:00
AS CIDR
45.9.148.0/24
CIDR
45.9.148.128/25
Registrant
Nice IT Customers Network
Address
28 Cork Street, Roseau, Dominica
City
Amsterdam
Postal code
1012 AB
Country
NL — Netherlands 🇳🇱
First indexed
2022-08-20 03:20:49
Last updated
2026-08-18 12:39:18

Malicious IPs in the same CIDR

45.9.148.50 45.9.148.37 45.9.148.65 45.9.148.138