85.217.140.36

Classification: Malicious

85.217.140.36 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-10. Network: AS209334 Modat B.V..

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-03-07 02:12:45 2026-09-10 09:08:03 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-03-07 02:12:42 2026-09-10 09:08:01 attacker malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2026-09-09 16:04:02 2026-09-09 16:04:02 attacker malicious-activity
Malicious Host CIArmy 2026-03-06 15:05:21 2026-09-08 20:02:08 attacker malicious-activity
Mail Spammer Barracuda 2026-03-06 15:05:29 2026-07-10 21:00:12 attacker malicious-activity
Port Scanner AbuseIPDB 2026-03-04 13:53:40 2026-07-10 20:09:02 anomalous-activity attacker malicious-activity reconnaissance
Bruteforce AbuseIPDB 2026-03-04 13:54:25 2026-07-10 18:34:59 attacker malicious-activity
DDoS Attacker AbuseIPDB 2026-03-04 17:31:22 2026-07-10 18:20:11 attacker malicious-activity
Known Attacker AbuseIPDB 2026-03-04 17:31:22 2026-07-10 18:20:11 attacker malicious-activity
Hacking AbuseIPDB 2026-03-04 12:53:23 2026-07-10 18:20:11 attacker malicious-activity
IMAP Attacker AbuseIPDB 2026-03-06 05:14:45 2026-07-10 17:18:00 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-03-05 21:03:34 2026-07-10 12:14:38 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-05 22:10:35 2026-07-10 12:14:38 anomalous-activity attacker malicious-activity
SSH Attacker AbuseIPDB 2026-03-04 13:54:48 2026-07-10 05:56:50 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-03-06 12:53:42 2026-07-10 01:11:07 attacker malicious-activity
Malicious Host AbuseIPDB 2026-03-04 17:17:05 2026-07-09 16:19:19 attacker compromised malicious-activity
Phishing AbuseIPDB 2026-04-22 19:00:54 2026-06-30 21:00:08 malicious-activity phishing
IoT Attacker AbuseIPDB 2026-03-04 18:42:20 2026-06-29 18:37:04 iot malicious-activity
FTP Attacker AbuseIPDB 2026-04-13 02:13:03 2026-06-25 07:47:30 attacker malicious-activity
Mail Spammer Blocklist.de 2026-05-12 08:04:16 2026-06-19 12:03:40 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-05-12 07:03:46 2026-06-19 11:03:24 attacker malicious-activity
SIP Attacker AbuseIPDB 2026-06-18 16:13:57 2026-06-18 16:13:57 attacker malicious-activity
Proxy AbuseIPDB 2026-06-17 20:40:48 2026-06-17 20:40:48 anonymization proxy
VPN AbuseIPDB 2026-04-29 10:35:43 2026-06-15 00:35:19 anonymization vpn
SQL Injection AbuseIPDB 2026-05-17 08:54:16 2026-05-29 10:36:13 attacker malicious-activity
DNS Poisoning AbuseIPDB 2026-04-18 15:18:04 2026-04-20 15:33:31 compromised malicious-activity

Tags

attacker imap pop3 sasl bot mail spam abuse

Whois information

AS name
AS209334 Modat B.V.
Registrant
Modat B.V.
City
Saint-Ouen
Postal code
93400
Country
FR — France 🇫🇷
First indexed
2026-03-06 15:05:21
Last updated
2026-09-10 09:08:26