63.135.161.122

Classification: Malicious

63.135.161.122 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-09. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • VPN node β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2025-03-01 07:38:23 2026-09-09 09:22:47 anonymization vpn
HTTP Spammer StopForumSpam.com 2024-06-21 05:05:03 2026-09-09 07:13:23 attacker malicious-activity
Hacking AbuseIPDB 2026-06-17 19:15:23 2026-09-07 09:10:57 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-06-17 07:30:04 2026-09-06 17:50:42 attacker malicious-activity
DDoS Attacker Blocklist.net.ua 2026-04-25 12:23:53 2026-09-05 16:23:34 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-06-18 19:53:49 2026-09-05 01:50:00 attacker malicious-activity
Bruteforce AbuseIPDB 2026-06-17 07:30:04 2026-09-05 01:50:00 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:25:36 2026-09-04 16:25:36 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-07-18 00:21:38 2026-09-02 18:30:51 attacker malicious-activity
Malicious Host AbuseIPDB 2026-06-23 19:50:03 2026-09-01 05:32:34 attacker compromised malicious-activity
HTTP bot Blocklist.de 2026-08-28 08:01:15 2026-08-28 08:01:15 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-06-17 21:00:08 2026-08-27 13:50:47 anomalous-activity attacker malicious-activity
VPN AbuseIPDB 2026-07-16 02:42:55 2026-07-16 02:42:55 anonymization
Suspicious Host AbuseIPDB 2024-11-11 07:17:40 2026-05-12 12:54:53 anomalous-activity
Proxy IPWhois.io 2025-08-07 21:03:27 2025-08-07 21:03:27 anonymization
Proxy FireHOL 2023-06-04 07:02:08 2023-07-05 20:54:56 anonymization
Bruteforce login attacker Blocklist.de 2023-03-02 02:06:33 2023-03-03 02:32:26 malicious-activity
HTTP Attacker Blocklist.de 2023-03-02 01:51:18 2023-03-03 02:17:55 malicious-activity

Tags

anonymization attacker login bruteforce bot joomla wordpress apache ddos rfi abuse spam

Whois information

AS name
AS206092 AS206092 Internet Utilities Europe and Asia Limited
AS registry
arin
AS date
2020-12-18 00:00:00
AS CIDR
63.135.161.0/24
CIDR
63.135.160.0/22
Registrant
AS206092 Internet Utilities Europe and Asia Limited
Address
184 East Snowy Egret Dr.
City
New York City
State
NY
Postal code
10203
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected]
First indexed
2023-03-02 01:51:18
Last updated
2026-09-09 09:22:49

Malicious IPs in the same CIDR

63.135.161.69 63.135.161.41 63.135.161.121 63.135.161.115 63.135.161.55 63.135.161.72 63.135.161.71 63.135.161.155 63.135.161.17 63.135.161.109 63.135.161.100 63.135.161.108 63.135.161.99 63.135.161.53 63.135.161.62 63.135.161.12 63.135.161.164 63.135.161.122 63.135.161.57 63.135.161.135 63.135.161.168 63.135.161.171 63.135.161.120 63.135.161.149 63.135.161.8