46.246.4.9

Classification: Malicious

46.246.4.9 is a malicious IP address. Linked to Dcrat malware. Reported by 7 threat sources, last seen 2026-09-01. Network: AS42708 Glesys AB.

Current activity

  • VPN node β€” Provides anonymization that can hide an attacker.

MITRE ATT&CK associations

Malware families: DCRAT (S9017)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2026-07-18 22:25:23 2026-09-01 15:22:13 anonymization vpn
Vjw0rm ThreatFox Abuse.ch 2026-08-10 17:45:11 2026-08-10 18:25:04 malicious-activity
DCRat ThreatFox Abuse.ch 2026-06-13 19:45:11 2026-06-13 20:25:04 malicious-activity S9017 DCRAT
Proxy IPWhois.io 2025-08-28 15:01:33 2025-08-28 15:01:33 anonymization
Malicious Host HoneyDB 2023-01-09 00:00:00 2023-01-09 00:00:00 malicious-activity
HTTP Spammer StopForumSpam.com 2021-01-26 20:23:01 2021-04-21 14:31:00 malicious-activity
HTTP Spammer Cleantalk.org 2020-04-05 00:52:59 2020-04-05 00:52:59
Bruteforce login attacker Blocklist.de 2019-12-21 00:40:07 2019-12-22 07:07:20
HTTP Attacker Blocklist.de 2019-12-21 00:37:00 2019-12-22 07:03:51
Anonymizer Maltiverse 2019-06-17 01:54:05 2019-06-17 01:54:05

Tags

anonymizer apache ddos rfi attacker login bruteforce bot joomla wordpress abuse port:8848 rat dcrat drb-ra darkcrystal rat vjw0rm port:7044

Whois information

AS name
AS42708 Glesys AB
AS registry
ripencc
AS date
2011-01-27 00:00:00
AS CIDR
46.246.0.0/17
Registrant
Glesys AB
City
Stockholm
Postal code
101 23
Country
SE β€” Sweden πŸ‡ΈπŸ‡ͺ
First indexed
2019-06-17 01:54:05
Last updated
2026-09-01 15:22:15

Malicious IPs in the same CIDR

46.246.3.226 46.246.8.130 46.246.8.138 46.246.44.53 46.246.84.10 46.246.97.3 46.246.122.104 46.246.122.76 46.246.106.43 46.246.3.244 46.246.122.121 46.246.6.66 46.246.4.9 46.246.3.206 46.246.8.121 46.246.41.155 46.246.41.154 46.246.14.6 46.246.3.234 46.246.3.193 46.246.3.241 46.246.39.245 46.246.6.16 46.246.123.27 46.246.4.16