85.203.44.238

Classification: Malicious

85.203.44.238 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-10. Network: AS42708 EXPRES 0 0.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Blocklist.de 2026-09-09 12:02:54 2026-09-10 12:02:17 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-09-09 11:02:22 2026-09-10 11:01:57 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-07-22 01:44:49 2026-01-25 04:10:27 anomalous-activity
HTTP bot Blocklist.de 2026-01-14 10:12:03 2026-01-15 05:20:07 malicious-activity
HTTP Spammer StopForumSpam.com 2024-02-17 19:10:01 2025-10-21 14:21:29 malicious-activity
HTTP Spammer Sblam 2024-02-17 16:56:53 2025-09-13 15:45:49 malicious-activity
VPN IPWhois.io 2025-03-08 22:44:38 2025-06-14 20:47:06 anonymization
HTTP Spammer Cleantalk.org 2024-03-09 09:30:54 2024-04-14 12:24:58 malicious-activity
Mail Spammer Abuseat.org 2024-02-17 16:56:53 2024-02-17 16:56:53

Tags

bot abuse attacker spam bruteforce imap pop3 sasl mail

Whois information

AS name
AS42708 EXPRES 0 0
AS registry
ripencc
AS date
2005-01-12 00:00:00
AS CIDR
85.203.44.0/24
CIDR
85.203.44.0/24
Registrant
EXPRES 0 0
Address
Falco IPR B.V. De Hoefsmid 11-13 1851 PZ Heiloo The Netherlands
City
Stockholm
Postal code
111 29
Country
SE β€” Sweden πŸ‡ΈπŸ‡ͺ
First indexed
2024-02-17 16:56:53
Last updated
2026-09-10 12:02:17

Malicious IPs in the same CIDR

85.203.44.130 85.203.44.14 85.203.44.153 85.203.44.237 85.203.44.151 85.203.44.238 85.203.44.242 85.203.44.207 85.203.44.7 85.203.44.56 85.203.44.254 85.203.44.26 85.203.44.90 85.203.44.109 85.203.44.156 85.203.44.178 85.203.44.228 85.203.44.31 85.203.44.62 85.203.44.106 85.203.44.229 85.203.44.232 85.203.44.244 85.203.44.144 85.203.44.139