79.135.105.168
Classification: Malicious
79.135.105.168 is a malicious IP address. Reported by 3 threat sources, last seen 2026-08-20. Network: AS212238 PROTONVPN.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| VPN ProtonVPN | Maltiverse Threat Observatory | 2025-07-22 19:23:09 | 2026-08-20 09:45:57 | anomalous-activity anonymization country_code:ar country_code:br country_code:ni industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:media-and-entertainment malicious-activity | |
| Proton | Maltiverse Threat Observatory | 2026-06-26 09:43:28 | 2026-06-27 09:45:52 | country_code:br industry:education-and-nonprofits | |
| Proxy | IPWhois.io | 2025-02-20 06:17:45 | 2025-04-27 12:29:40 | anonymization | |
| HTTP Spammer | StopForumSpam.com | 2025-02-20 01:56:06 | 2025-04-27 12:29:37 | malicious-activity |
Tags
bot abuse port:1194 port:51820 port:992 port:5555 port:500 port:4500 port:1701 port:1723 port:443 port:4569 port:5060 port:9001 port:5959 port:12233Whois information
- AS name
- AS212238 PROTONVPN
- AS registry
- ripencc
- AS date
- 2007-10-31 00:00:00
- AS CIDR
- 79.135.105.0/24
- Registrant
- PROTONVPN
- City
- Marseille
- Postal code
- 13000
- Country
- FR — France 🇫🇷
- First indexed
- 2025-02-20 01:56:06
- Last updated
- 2026-08-20 17:34:12
Malicious IPs in the same CIDR
79.135.105.141 79.135.105.1 79.135.105.152 79.135.105.44 79.135.105.81 79.135.105.194 79.135.105.46 79.135.105.2 79.135.105.204 79.135.105.168 79.135.105.84 79.135.105.160