54.37.211.125
Classification: Malicious
54.37.211.125 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-15. Network: AS16276 OVH SAS.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Open proxy — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Proxy | IPWhois.io | 2025-06-16 02:41:14 | 2026-08-15 14:40:35 | anonymization proxy | |
| Mail Spammer | Barracuda | 2022-12-29 11:42:18 | 2026-08-15 14:40:35 | attacker malicious-activity | |
| Proxy | FireHOL | 2022-12-31 23:04:03 | 2025-10-07 07:48:33 | anonymization | |
| Anonymizer | FireHol | 2022-12-29 11:42:17 | 2022-12-29 23:02:04 | anonymization | |
| HTTP Attacker | Blocklist.de | 2022-10-25 02:08:23 | 2022-11-08 00:46:56 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2022-10-25 02:20:49 | 2022-11-07 01:59:30 | malicious-activity | |
| IMAP Attacker | Blocklist.de | 2022-09-16 02:05:15 | 2022-10-22 01:56:18 | malicious-activity | |
| Mail Spammer | Blocklist.de | 2022-09-17 02:04:59 | 2022-10-21 01:17:37 | malicious-activity | |
| SSH Attacker | Blocklist.de | 2022-07-24 02:11:23 | 2022-09-18 02:13:42 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2022-07-14 05:21:30 | 2022-09-16 04:53:02 | malicious-activity |
Tags
anonymization apache ddos rfi attacker login bruteforce bot joomla wordpress imap pop3 sasl mail spam ssh abuseWhois information
- AS name
- AS16276 OVH SAS
- AS registry
- ripencc
- AS date
- 1992-03-17 00:00:00
- AS CIDR
- 54.37.0.0/16
- Registrant
- OVH SAS
- City
- Paris
- Postal code
- 75004
- Country
- FR — France 🇫🇷
- First indexed
- 2022-07-14 05:21:30
- Last updated
- 2026-08-15 14:40:36
Malicious IPs in the same CIDR
54.37.5.18 54.37.18.137 54.37.74.231 54.37.229.48 54.37.11.28 54.37.10.124 54.37.77.212 54.37.211.125 54.37.130.150 54.37.234.111 54.37.131.158