85.203.20.53
Classification: Suspicious
85.203.20.53 is a suspicious IP address. Reported by 5 threat sources, last seen 2026-03-01. Network: AS212238 EXPRES 0 0 0.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Suspicious Host | AbuseIPDB | 2024-08-06 01:39:08 | 2026-03-01 10:25:44 | anomalous-activity | |
| VPN | IPWhois.io | 2025-02-26 11:23:03 | 2025-10-28 14:38:55 | anonymization | |
| HTTP Spammer | Cleantalk.org | 2024-11-05 21:41:52 | 2024-11-05 21:41:52 | malicious-activity | |
| DDoS attack on site on-planet.com | Blocklist.net.ua | 2023-03-07 07:35:29 | 2023-09-07 04:37:55 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2019-07-10 03:11:05 | 2019-07-10 03:11:05 |
Tags
abuse botWhois information
- AS name
- AS212238 EXPRES 0 0 0
- AS registry
- ripencc
- AS date
- 2005-01-12 00:00:00
- AS CIDR
- 85.203.20.0/24
- Registrant
- EXPRES 0 0 0
- City
- Zagreb
- Postal code
- 10106
- Country
- HR — Croatia 🇭🇷
- First indexed
- 2019-07-10 03:11:05
- Last updated
- 2026-03-02 01:43:06
Malicious IPs in the same CIDR
85.203.20.13 85.203.20.16 85.203.20.19 85.203.20.33 85.203.20.4 85.203.20.64 85.203.20.56 85.203.20.81 85.203.20.7 85.203.20.93 85.203.20.80 85.203.20.23