60.223.254.202

Classification: Malicious

60.223.254.202 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-13. Network: AS4837 China Unicom Shanxi province network.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Blocklist.de 2026-03-16 08:05:37 2026-09-13 12:01:56 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-03-16 07:06:10 2026-09-13 11:01:36 attacker malicious-activity
Mail Spammer Barracuda 2026-01-29 04:41:43 2026-08-13 16:41:38 attacker malicious-activity
Malicious Host AbuseIPDB 2026-01-27 17:57:02 2026-06-07 22:22:22 compromised malicious-activity
Mail Spammer AbuseIPDB 2025-12-27 00:34:15 2026-03-14 17:16:12 malicious-activity
Hacking AbuseIPDB 2025-12-27 00:34:15 2026-03-14 04:05:06 malicious-activity
Bruteforce AbuseIPDB 2025-12-27 00:34:15 2026-03-13 16:51:12 malicious-activity
Port Scanner AbuseIPDB 2026-01-29 16:59:27 2026-03-12 05:25:33 anomalous-activity
Suspicious Host AbuseIPDB 2026-01-28 08:53:45 2026-03-11 21:24:02 anomalous-activity
IMAP Attacker AbuseIPDB 2026-02-13 22:07:33 2026-02-28 20:30:25 malicious-activity
Proxy AbuseIPDB 2026-02-19 21:00:00 2026-02-19 21:00:00 anonymization
DDoS Attacker AbuseIPDB 2026-02-10 18:20:54 2026-02-19 21:00:00 malicious-activity
SSH Attacker AbuseIPDB 2026-02-07 11:29:57 2026-02-07 11:29:57 malicious-activity

Tags

attacker imap pop3 sasl bot mail spam

Whois information

AS name
AS4837 China Unicom Shanxi province network
Registrant
China Unicom Shanxi province network
City
Taiyuan
Postal code
030002
Country
CN — China 🇨🇳
First indexed
2026-01-29 04:41:31
Last updated
2026-09-13 12:01:56