79.135.105.168

Classification: Malicious

79.135.105.168 is a malicious IP address. Reported by 3 threat sources, last seen 2026-08-20. Network: AS212238 PROTONVPN.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN ProtonVPN Maltiverse Threat Observatory 2025-07-22 19:23:09 2026-08-20 09:45:57 anomalous-activity anonymization country_code:ar country_code:br country_code:ni industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:media-and-entertainment malicious-activity
Proton Maltiverse Threat Observatory 2026-06-26 09:43:28 2026-06-27 09:45:52 country_code:br industry:education-and-nonprofits
Proxy IPWhois.io 2025-02-20 06:17:45 2025-04-27 12:29:40 anonymization
HTTP Spammer StopForumSpam.com 2025-02-20 01:56:06 2025-04-27 12:29:37 malicious-activity

Tags

bot abuse port:1194 port:51820 port:992 port:5555 port:500 port:4500 port:1701 port:1723 port:443 port:4569 port:5060 port:9001 port:5959 port:12233

Whois information

AS name
AS212238 PROTONVPN
AS registry
ripencc
AS date
2007-10-31 00:00:00
AS CIDR
79.135.105.0/24
Registrant
PROTONVPN
City
Marseille
Postal code
13000
Country
FR — France 🇫🇷
First indexed
2025-02-20 01:56:06
Last updated
2026-08-20 17:34:12

Malicious IPs in the same CIDR

79.135.105.141 79.135.105.1 79.135.105.152 79.135.105.44 79.135.105.81 79.135.105.194 79.135.105.46 79.135.105.2 79.135.105.204 79.135.105.168 79.135.105.84 79.135.105.160