85.203.20.63

Classification: Suspicious

85.203.20.63 is a suspicious IP address. Reported by 7 threat sources, last seen 2026-03-15. Network: AS212238 EXPRES 0 0 0.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Suspicious Host AbuseIPDB 2024-08-04 01:11:48 2026-03-15 03:45:13 anomalous-activity
HTTP Spammer Sblam 2025-09-28 07:07:51 2025-09-28 07:07:51 malicious-activity
HTTP Spammer Cleantalk.org 2025-07-21 14:30:39 2025-07-21 14:30:39 malicious-activity
VPN IPWhois.io 2025-05-16 07:28:16 2025-05-17 07:23:34 anonymization
Bruteforce login attacker Blocklist.de 2024-08-09 03:29:24 2024-08-10 09:44:59 malicious-activity
HTTP Attacker Blocklist.de 2024-08-09 02:40:42 2024-08-10 08:52:55 malicious-activity
DDoS attack on site on-planet.com Blocklist.net.ua 2023-03-07 07:35:31 2023-09-07 04:37:57 malicious-activity
HTTP Spammer StopForumSpam.com 2023-04-12 21:24:35 2023-07-07 20:02:42 malicious-activity

Tags

abuse bot apache ddos rfi attacker login bruteforce joomla wordpress

Whois information

AS name
AS212238 EXPRES 0 0 0
AS registry
ripencc
AS date
2005-01-12 00:00:00
AS CIDR
85.203.20.0/24
CIDR
85.203.20.0/24
Registrant
EXPRES 0 0 0
Address
Falco IPR B.V. De Hoefsmid 11-13 1851 PZ Heiloo The Netherlands
City
Zagreb
Postal code
10106
Country
HR — Croatia 🇭🇷
First indexed
2023-03-07 07:35:31
Last updated
2026-03-16 01:35:51

Malicious IPs in the same CIDR

85.203.20.13 85.203.20.16 85.203.20.19 85.203.20.33 85.203.20.4 85.203.20.64 85.203.20.56 85.203.20.81 85.203.20.7 85.203.20.93 85.203.20.80 85.203.20.23