46.246.4.3
Classification: Suspicious
46.246.4.3 is a suspicious IP address. Linked to Njrat, Asyncrat malware. Reported by 10 threat sources, last seen 2026-06-29.
Current activity
- VPN node β Provides anonymization that can hide an attacker.
MITRE ATT&CK associations
Malware families: NJRAT (S0385) ASYNCRAT (S1087)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| VPN | IPWhois.io | 2025-01-16 11:48:22 | 2026-06-29 09:47:28 | anonymization | |
| Proxy | IPWhois.io | 2025-08-28 15:01:32 | 2025-08-28 15:01:32 | anonymization | |
| AsyncRAT | ThreatFox Abuse.ch | 2025-08-04 08:18:02 | 2025-08-06 06:19:12 | malicious-activity | S1087 AsyncRAT |
| Vjw0rm | ThreatFox Abuse.ch | 2025-08-04 02:45:11 | 2025-08-06 02:19:10 | malicious-activity | |
| Asyncrat | Maltrail | 2025-03-27 14:19:34 | 2025-03-27 14:19:34 | malicious-activity | S1087 AsyncRAT |
| DCRat | ThreatFox Abuse.ch | 2024-06-13 07:18:35 | 2025-03-03 00:13:22 | malicious-activity | |
| Proxy | FireHOL | 2024-06-09 11:21:47 | 2025-02-02 23:31:10 | anonymization | |
| NjRAT | ThreatFox Abuse.ch | 2023-01-27 13:17:39 | 2023-01-29 12:18:42 | malicious-activity | S0385 njRAT |
| Anonymizer | Maltiverse Research Team | 2021-05-18 19:24:35 | 2021-05-22 22:13:30 | anonymizer | |
| Parasite SEO | Blocklist.net.ua | 2021-01-04 08:28:35 | 2021-01-04 08:28:35 | ||
| HTTP Spammer | StopForumSpam.com | 2020-04-08 03:28:57 | 2020-12-22 22:40:53 | malicious-activity | |
| Parasite traffic on site fleur-cosmetics.com.ua. | Blocklist.net.ua | 2020-04-07 01:23:00 | 2020-04-07 07:37:41 | ||
| Bruteforce login attacker | Blocklist.de | 2019-06-10 01:32:49 | 2019-11-04 07:02:19 | ||
| HTTP Attacker | Blocklist.de | 2019-06-10 01:21:06 | 2019-11-04 06:59:22 | ||
| HTTP Spammer | Cleantalk.org | 2019-06-10 03:22:03 | 2019-06-10 03:22:03 | ||
| Anonymizer | Maltiverse | 2019-05-31 13:47:39 | 2019-05-31 13:47:39 |
Tags
njrat port:415 bladabindi anonymizer apache ddos rfi attacker login bruteforce bot joomla wordpress abuse anonymization dcrat portlane www.portlane.com port:6000 darkcrystal rat port:9000 as42708 c2 censys portlane rat port:5000 glesys port:8080 port:8887 vjw0rm port:3049 port:4068 asyncratWhois information
- AS name
- AS42708 Loxodonta Ab Internet
- AS registry
- ripencc
- AS date
- 2011-01-27 00:00:00
- AS CIDR
- 46.246.0.0/17
- CIDR
- 46.246.4.0/23
- Registrant
- Loxodonta Ab Internet
- Address
- Box 6322 102 35 Stockholm Sweden
- City
- Stockholm
- Postal code
- 111 29
- Country
- SE β Sweden πΈπͺ
- Contact email
- [email protected]
- First indexed
- 2019-05-31 13:47:39
- Last updated
- 2026-06-29 09:47:29
Malicious IPs in the same CIDR
46.246.8.121 46.246.97.3 46.246.106.43 46.246.122.83 46.246.3.226 46.246.8.130 46.246.8.138 46.246.44.53 46.246.84.10 46.246.122.104 46.246.122.76 46.246.3.244 46.246.122.121 46.246.6.66 46.246.4.9 46.246.3.206 46.246.41.155 46.246.41.154 46.246.14.6 46.246.3.234 46.246.3.193 46.246.3.241 46.246.39.245 46.246.6.16 46.246.123.27