85.113.49.119

Classification: Malicious

85.113.49.119 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-05. Network: AS34533 JSC ER-Telecom Holding.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Hacking AbuseIPDB 2026-08-30 06:00:04 2026-09-05 06:00:17 attacker malicious-activity
Port Scanner AbuseIPDB 2026-08-29 14:05:10 2026-09-05 06:00:17 anomalous-activity attacker malicious-activity reconnaissance
SSH Attacker AbuseIPDB 2026-08-29 12:00:52 2026-09-05 06:00:17 attacker malicious-activity
Bruteforce AbuseIPDB 2026-08-29 11:22:53 2026-09-05 06:00:17 attacker malicious-activity
SSH Attacker Blocklist.de 2026-08-30 14:01:00 2026-08-30 14:01:00 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-08-30 01:00:20 2026-08-30 01:00:20 attacker malicious-activity
FTP Attacker AbuseIPDB 2026-08-29 15:21:30 2026-08-29 15:21:30 attacker malicious-activity
Proxy FireHOL 2023-01-01 05:04:41 2024-03-27 07:31:48 anonymization
Anonymizer FireHol 2022-12-29 17:41:59 2022-12-30 05:14:49 anonymization
Anonymizer Maltiverse Research Team 2020-11-21 18:18:05 2021-05-23 02:05:30 anonymizer
Anonymizer Maltiverse 2020-05-03 02:47:22 2020-05-03 02:47:22

Tags

anonymization anonymizer ssh bruteforce bot

Whois information

AS name
AS34533 JSC ER-Telecom Holding
AS registry
ripencc
AS date
2005-02-08 00:00:00
AS CIDR
85.113.32.0/19
CIDR
85.113.48.0/21
Registrant
JSC ER-Telecom Holding
Address
Partizanskaya str., 86 Samara, Russia, 443070
City
Samara
Postal code
443013
Country
RU — Russian Federation 🇷🇺
First indexed
2020-05-03 02:47:22
Last updated
2026-09-09 01:56:45

Malicious IPs in the same CIDR

85.113.35.205 85.113.49.119 85.113.43.181 85.113.39.168 85.113.34.84 85.113.47.102