85.217.140.51

Classification: Malicious

85.217.140.51 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-12. Network: AS209334 Modat B.V..

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Empty reason Blocklist.net.ua 2026-09-12 16:06:19 2026-09-12 16:06:19 attacker malicious-activity
Port Scanner AbuseIPDB 2026-03-04 13:48:59 2026-09-12 01:25:25 anomalous-activity attacker malicious-activity reconnaissance
Hacking AbuseIPDB 2026-03-04 12:51:19 2026-09-12 01:25:25 attacker malicious-activity
Bruteforce AbuseIPDB 2026-03-04 13:49:58 2026-09-12 01:13:50 attacker malicious-activity
Malicious Host AbuseIPDB 2026-03-04 21:45:06 2026-09-11 21:07:33 attacker compromised malicious-activity
DDoS Attacker AbuseIPDB 2026-03-04 20:01:24 2026-09-11 04:30:01 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-03-06 00:46:13 2026-09-11 03:07:39 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-03-05 00:15:34 2026-09-11 01:01:05 attacker malicious-activity
SQL Injection AbuseIPDB 2026-03-16 07:44:55 2026-09-10 16:37:28 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-03-04 13:49:58 2026-09-10 16:30:13 attacker malicious-activity
Proxy AbuseIPDB 2026-08-29 22:41:21 2026-09-10 13:51:43 anonymization proxy
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-03-07 02:12:46 2026-09-10 09:08:03 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-03-07 02:12:43 2026-09-10 09:08:01 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-05 00:04:20 2026-09-10 02:23:14 anomalous-activity attacker malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2026-09-09 16:04:03 2026-09-09 16:04:03 attacker malicious-activity reconnaissance
Malicious Host CIArmy 2026-03-06 15:05:21 2026-09-08 20:02:08 attacker malicious-activity
SIP Attacker AbuseIPDB 2026-04-08 12:31:17 2026-09-08 14:40:47 attacker malicious-activity
IoT Attacker AbuseIPDB 2026-03-16 11:03:47 2026-09-08 13:59:33 iot malicious-activity
Known Attacker AbuseIPDB 2026-03-04 20:01:24 2026-09-06 10:50:52 attacker malicious-activity
DNS Poisoning AbuseIPDB 2026-03-08 01:43:32 2026-08-29 00:25:48 compromised malicious-activity
DNS Compromise AbuseIPDB 2026-04-09 17:53:20 2026-08-27 23:44:38 compromised malicious-activity
FTP Attacker AbuseIPDB 2026-03-12 03:11:11 2026-08-07 15:33:27 attacker malicious-activity
Mail Spammer Blocklist.de 2026-04-08 08:07:01 2026-07-03 12:02:41 attacker malicious-activity
IMAP Attacker AbuseIPDB 2026-03-07 00:59:48 2026-06-30 05:24:10 malicious-activity
RedTail ThreatFox Abuse.ch 2026-06-26 09:02:21 2026-06-26 09:25:05 malicious-activity
Phishing AbuseIPDB 2026-03-06 06:00:09 2026-06-25 08:00:07 malicious-activity
VPN AbuseIPDB 2026-04-23 12:44:21 2026-06-15 03:43:36 anonymization
IMAP Attacker Blocklist.de 2026-06-12 11:02:14 2026-06-13 11:02:27 malicious-activity
Bruteforce login attacker Blocklist.de 2026-05-06 05:02:01 2026-05-06 05:02:01 malicious-activity
HTTP Attacker Blocklist.de 2026-05-06 03:02:24 2026-05-06 03:02:24 malicious-activity

Tags

mail spam apache ddos rfi attacker login bruteforce bot joomla wordpress imap pop3 sasl port:2375 docker-api abuse

Whois information

AS name
AS209334 Modat B.V.
Registrant
Modat B.V.
City
Gravelines
Postal code
59820
Country
FR — France 🇫🇷
First indexed
2026-03-06 00:08:15
Last updated
2026-09-12 16:06:19