85.217.140.28
Classification: Malicious
85.217.140.28 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-10. Network: AS209334 Modat B.V..
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
- IoT threat — Seen attacking IoT devices.
- Open proxy — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Port Scanner | AbuseIPDB | 2026-02-10 10:16:00 | 2026-09-10 04:55:37 | anomalous-activity attacker malicious-activity reconnaissance | |
| HTTP Scrapper | AbuseIPDB | 2026-02-11 11:56:41 | 2026-09-10 01:13:38 | anomalous-activity attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-02-10 15:30:19 | 2026-09-10 01:13:38 | attacker malicious-activity | |
| Unauthorized scanning of hosts | Blocklist.net.ua | 2026-09-09 16:04:02 | 2026-09-09 16:04:02 | attacker malicious-activity reconnaissance | |
| HTTP Attacker | AbuseIPDB | 2026-02-11 02:00:15 | 2026-09-09 12:26:01 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2026-02-10 10:16:00 | 2026-09-09 12:26:01 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-02-10 10:16:00 | 2026-09-09 08:50:53 | attacker compromised malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-02-13 02:26:46 | 2026-09-08 09:07:23 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-02-13 02:26:40 | 2026-09-08 09:07:22 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-02-13 04:31:51 | 2026-09-07 01:55:06 | attacker malicious-activity | |
| Malicious Host | CIArmy | 2026-02-12 15:10:43 | 2026-09-06 20:01:27 | attacker malicious-activity | |
| SQL Injection | AbuseIPDB | 2026-02-11 05:41:47 | 2026-09-06 13:09:32 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-02-10 23:08:46 | 2026-09-06 12:42:06 | attacker malicious-activity | |
| Known Attacker | AbuseIPDB | 2026-02-10 18:00:52 | 2026-09-05 05:50:47 | attacker malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-02-10 18:00:52 | 2026-09-05 05:50:47 | attacker malicious-activity | |
| Proxy | AbuseIPDB | 2026-06-25 03:14:35 | 2026-09-05 01:57:01 | anonymization proxy | |
| Phishing | AbuseIPDB | 2026-09-03 03:00:07 | 2026-09-03 03:00:07 | malicious-activity phishing | |
| IoT Attacker | AbuseIPDB | 2026-03-21 04:59:47 | 2026-09-02 15:39:08 | iot malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-02-25 11:09:04 | 2026-08-29 03:50:04 | attacker malicious-activity | |
| DNS Compromise | AbuseIPDB | 2026-04-14 10:40:04 | 2026-07-10 00:26:15 | compromised malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2026-02-13 12:25:03 | 2026-07-09 07:28:25 | attacker malicious-activity | |
| Mail Spammer | Blocklist.de | 2026-06-27 12:03:27 | 2026-06-28 12:03:10 | attacker malicious-activity | |
| IMAP Attacker | Blocklist.de | 2026-06-27 11:03:11 | 2026-06-28 11:02:52 | attacker malicious-activity |
Tags
attacker imap pop3 sasl bot mail spam abuseWhois information
- AS name
- AS209334 Modat B.V.
- Registrant
- Modat B.V.
- City
- Gravelines
- Postal code
- 59820
- Country
- FR — France 🇫🇷
- First indexed
- 2026-02-11 00:02:56
- Last updated
- 2026-09-10 05:56:17