83.69.236.128
Classification: Malicious
83.69.236.128 is a malicious IP address. Linked to Socgholish malware. Reported by 3 threat sources, last seen 2026-09-03. Network: AS12616 Citytelecom LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
MITRE ATT&CK associations
Malware families: SOCGHOLISH (S1124)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2026-09-03 02:55:10 | 2026-09-03 02:55:10 | attacker malicious-activity | |
| FAKEUPDATES | ThreatFox Abuse.ch | 2024-02-28 09:17:06 | 2024-03-01 08:17:53 | malicious-activity | S1124 SocGholish |
| Mail Spammer | Abuseat.org | 2024-02-28 09:17:16 | 2024-02-28 09:17:16 |
Tags
keitarotds socgholish port:443 fakeupdateWhois information
- AS name
- AS12616 Citytelecom LLC
- AS registry
- ripencc
- AS date
- 2004-06-04 00:00:00
- AS CIDR
- 83.69.236.0/24
- CIDR
- 83.69.236.0/24
- Registrant
- Citytelecom LLC
- Address
- 105120 Russia Moscow Electrolitniy dr, 3/47
- City
- Moscow
- Postal code
- 109012
- Country
- RU — Russian Federation 🇷🇺
- Contact email
- [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2024-02-28 09:17:06
- Last updated
- 2026-09-03 02:55:11