54.37.211.125

Classification: Malicious

54.37.211.125 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-15. Network: AS16276 OVH SAS.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Proxy IPWhois.io 2025-06-16 02:41:14 2026-08-15 14:40:35 anonymization proxy
Mail Spammer Barracuda 2022-12-29 11:42:18 2026-08-15 14:40:35 attacker malicious-activity
Proxy FireHOL 2022-12-31 23:04:03 2025-10-07 07:48:33 anonymization
Anonymizer FireHol 2022-12-29 11:42:17 2022-12-29 23:02:04 anonymization
HTTP Attacker Blocklist.de 2022-10-25 02:08:23 2022-11-08 00:46:56 malicious-activity
Bruteforce login attacker Blocklist.de 2022-10-25 02:20:49 2022-11-07 01:59:30 malicious-activity
IMAP Attacker Blocklist.de 2022-09-16 02:05:15 2022-10-22 01:56:18 malicious-activity
Mail Spammer Blocklist.de 2022-09-17 02:04:59 2022-10-21 01:17:37 malicious-activity
SSH Attacker Blocklist.de 2022-07-24 02:11:23 2022-09-18 02:13:42 malicious-activity
HTTP Spammer StopForumSpam.com 2022-07-14 05:21:30 2022-09-16 04:53:02 malicious-activity

Tags

anonymization apache ddos rfi attacker login bruteforce bot joomla wordpress imap pop3 sasl mail spam ssh abuse

Whois information

AS name
AS16276 OVH SAS
AS registry
ripencc
AS date
1992-03-17 00:00:00
AS CIDR
54.37.0.0/16
Registrant
OVH SAS
City
Paris
Postal code
75004
Country
FR — France 🇫🇷
First indexed
2022-07-14 05:21:30
Last updated
2026-08-15 14:40:36

Malicious IPs in the same CIDR

54.37.5.18 54.37.18.137 54.37.74.231 54.37.229.48 54.37.11.28 54.37.10.124 54.37.77.212 54.37.211.125 54.37.130.150 54.37.234.111 54.37.131.158