83.69.236.128

Classification: Malicious

83.69.236.128 is a malicious IP address. Linked to Socgholish malware. Reported by 3 threat sources, last seen 2026-09-03. Network: AS12616 Citytelecom LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: SOCGHOLISH (S1124)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2026-09-03 02:55:10 2026-09-03 02:55:10 attacker malicious-activity
FAKEUPDATES ThreatFox Abuse.ch 2024-02-28 09:17:06 2024-03-01 08:17:53 malicious-activity S1124 SocGholish
Mail Spammer Abuseat.org 2024-02-28 09:17:16 2024-02-28 09:17:16

Tags

keitarotds socgholish port:443 fakeupdate

Whois information

AS name
AS12616 Citytelecom LLC
AS registry
ripencc
AS date
2004-06-04 00:00:00
AS CIDR
83.69.236.0/24
CIDR
83.69.236.0/24
Registrant
Citytelecom LLC
Address
105120 Russia Moscow Electrolitniy dr, 3/47
City
Moscow
Postal code
109012
Country
RU — Russian Federation 🇷🇺
Contact email
[email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
First indexed
2024-02-28 09:17:06
Last updated
2026-09-03 02:55:11

Malicious IPs in the same CIDR

83.69.236.128