85.217.145.55

Classification: Malicious

85.217.145.55 is a malicious IP address. Linked to Warzonerat malware. Reported by 3 threat sources, last seen 2026-09-03. Network: AS16276 Neterra Ltd..

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: WARZONERAT (S0670)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2023-09-26 11:18:12 2026-09-03 21:26:12 attacker malicious-activity
Ave Maria ThreatFox Abuse.ch 2023-09-26 11:18:11 2023-09-28 10:54:10 malicious-activity S0670 WarzoneRAT
Mail Spammer Abuseat.org 2023-09-26 11:18:12 2023-09-26 11:18:12

Tags

avemariarat c2 historicalandnew warzonerat port:5200 ave_maria warzone rat avemaria

Whois information

AS name
AS16276 Neterra Ltd.
AS registry
ripencc
AS date
2005-01-18 00:00:00
AS CIDR
NA
CIDR
85.217.144.0/23
Registrant
Neterra Ltd.
Address
9 Vitoshki Kambani Street, Kambanite Green Offices, Fl. 3 1756 Sofia BULGARIA
City
London
Postal code
SW1Y 5
Country
GB — United Kingdom 🇬🇧
Contact email
[email protected]
First indexed
2023-09-26 11:18:11
Last updated
2026-09-03 21:26:12

Malicious IPs in the same CIDR

37.32.1.184 64.23.136.241 37.32.1.239 195.177.94.158 89.194.58.1 217.154.85.211 46.148.39.48 203.188.168.3 5.149.105.158 5.222.37.1 85.217.145.55 41.71.176.182 37.252.178.5 37.32.1.201 37.32.1.218 37.32.1.245 37.32.1.189 37.32.1.204 37.32.1.220 37.32.1.222 37.32.1.224 37.32.1.229 37.32.1.168 37.32.1.172 37.32.1.178