85.217.140.28

Classification: Malicious

85.217.140.28 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-10. Network: AS209334 Modat B.V..

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Port Scanner AbuseIPDB 2026-02-10 10:16:00 2026-09-10 04:55:37 anomalous-activity attacker malicious-activity reconnaissance
HTTP Scrapper AbuseIPDB 2026-02-11 11:56:41 2026-09-10 01:13:38 anomalous-activity attacker malicious-activity
Bruteforce AbuseIPDB 2026-02-10 15:30:19 2026-09-10 01:13:38 attacker malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2026-09-09 16:04:02 2026-09-09 16:04:02 attacker malicious-activity reconnaissance
HTTP Attacker AbuseIPDB 2026-02-11 02:00:15 2026-09-09 12:26:01 attacker malicious-activity
Hacking AbuseIPDB 2026-02-10 10:16:00 2026-09-09 12:26:01 attacker malicious-activity
Malicious Host AbuseIPDB 2026-02-10 10:16:00 2026-09-09 08:50:53 attacker compromised malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-02-13 02:26:46 2026-09-08 09:07:23 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-02-13 02:26:40 2026-09-08 09:07:22 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-02-13 04:31:51 2026-09-07 01:55:06 attacker malicious-activity
Malicious Host CIArmy 2026-02-12 15:10:43 2026-09-06 20:01:27 attacker malicious-activity
SQL Injection AbuseIPDB 2026-02-11 05:41:47 2026-09-06 13:09:32 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-02-10 23:08:46 2026-09-06 12:42:06 attacker malicious-activity
Known Attacker AbuseIPDB 2026-02-10 18:00:52 2026-09-05 05:50:47 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-02-10 18:00:52 2026-09-05 05:50:47 attacker malicious-activity
Proxy AbuseIPDB 2026-06-25 03:14:35 2026-09-05 01:57:01 anonymization proxy
Phishing AbuseIPDB 2026-09-03 03:00:07 2026-09-03 03:00:07 malicious-activity phishing
IoT Attacker AbuseIPDB 2026-03-21 04:59:47 2026-09-02 15:39:08 iot malicious-activity
FTP Attacker AbuseIPDB 2026-02-25 11:09:04 2026-08-29 03:50:04 attacker malicious-activity
DNS Compromise AbuseIPDB 2026-04-14 10:40:04 2026-07-10 00:26:15 compromised malicious-activity
IMAP Attacker AbuseIPDB 2026-02-13 12:25:03 2026-07-09 07:28:25 attacker malicious-activity
Mail Spammer Blocklist.de 2026-06-27 12:03:27 2026-06-28 12:03:10 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-06-27 11:03:11 2026-06-28 11:02:52 attacker malicious-activity

Tags

attacker imap pop3 sasl bot mail spam abuse

Whois information

AS name
AS209334 Modat B.V.
Registrant
Modat B.V.
City
Gravelines
Postal code
59820
Country
FR — France 🇫🇷
First indexed
2026-02-11 00:02:56
Last updated
2026-09-10 05:56:17