5.79.79.210
Classification: Suspicious
5.79.79.210 is a suspicious IP address. Reported by 5 threat sources, last seen 2023-09-24. Network: AS60781 Leaseweb Netherlands B.V..
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RedLine Stealer | ThreatFox Abuse.ch | 2023-09-22 17:17:02 | 2023-09-24 16:18:20 | malicious-activity | |
| Vawtrak | Bambernek | 2019-12-19 00:37:11 | 2019-12-19 00:37:11 | ||
| apt | Maltiverse Research Team | 2019-10-08 15:59:11 | 2019-10-08 15:59:11 | ||
| Generic.Malware | Hybrid-Analysis | 2018-07-24 16:15:10 | 2019-03-18 23:30:25 | ||
| virut | Maltiverse Research Team | 2019-02-27 01:27:27 | 2019-02-27 01:27:27 | ||
| Trojan.APosT | Hybrid-Analysis | 2019-02-23 04:00:56 | 2019-02-23 04:00:56 | ||
| Spamming | Alienvault Ip Reputation Database | 2018-09-03 06:42:05 | 2019-01-28 06:35:54 | ||
| Simda | Bambernek | 2018-08-18 06:46:27 | 2018-08-18 06:46:27 | ||
| banjori | Bambernek | 2018-07-05 06:28:55 | 2018-07-05 06:28:55 |
Tags
redlinestealer port:80 malware banjori c&c simda c2 dga apt vawtrakWhois information
- AS name
- AS60781 Leaseweb Netherlands B.V.
- AS registry
- ripencc
- AS date
- 2012-06-14 00:00:00
- AS CIDR
- 5.79.64.0/18
- Registrant
- Leaseweb Netherlands B.V.
- City
- Amsterdam
- Postal code
- 1012 JS
- Country
- NL — Netherlands 🇳🇱
- First indexed
- 2018-07-05 06:28:55
- Last updated
- 2025-12-28 04:33:15
Malicious IPs in the same CIDR
5.79.98.35 5.79.86.16 5.79.64.140 5.79.83.217 5.79.115.233 5.79.71.244 5.79.66.19 5.79.109.48 5.79.72.113 5.79.77.33 5.79.78.92 5.79.73.149