85.217.145.55
Classification: Malicious
85.217.145.55 is a malicious IP address. Linked to Warzonerat malware. Reported by 3 threat sources, last seen 2026-09-03. Network: AS16276 Neterra Ltd..
Current activity
- Known attacker — Seen launching attacks over the Internet.
MITRE ATT&CK associations
Malware families: WARZONERAT (S0670)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2023-09-26 11:18:12 | 2026-09-03 21:26:12 | attacker malicious-activity | |
| Ave Maria | ThreatFox Abuse.ch | 2023-09-26 11:18:11 | 2023-09-28 10:54:10 | malicious-activity | S0670 WarzoneRAT |
| Mail Spammer | Abuseat.org | 2023-09-26 11:18:12 | 2023-09-26 11:18:12 |
Tags
avemariarat c2 historicalandnew warzonerat port:5200 ave_maria warzone rat avemariaWhois information
- AS name
- AS16276 Neterra Ltd.
- AS registry
- ripencc
- AS date
- 2005-01-18 00:00:00
- AS CIDR
- NA
- CIDR
- 85.217.144.0/23
- Registrant
- Neterra Ltd.
- Address
- 9 Vitoshki Kambani Street, Kambanite Green Offices, Fl. 3 1756 Sofia BULGARIA
- City
- London
- Postal code
- SW1Y 5
- Country
- GB — United Kingdom 🇬🇧
- Contact email
- [email protected]
- First indexed
- 2023-09-26 11:18:11
- Last updated
- 2026-09-03 21:26:12
Malicious IPs in the same CIDR
37.32.1.184 64.23.136.241 37.32.1.239 195.177.94.158 89.194.58.1 217.154.85.211 46.148.39.48 203.188.168.3 5.149.105.158 5.222.37.1 85.217.145.55 41.71.176.182 37.252.178.5 37.32.1.201 37.32.1.218 37.32.1.245 37.32.1.189 37.32.1.204 37.32.1.220 37.32.1.222 37.32.1.224 37.32.1.229 37.32.1.168 37.32.1.172 37.32.1.178