85.237.212.9

Classification: Malicious

85.237.212.9 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-05. Network: AS206092 Private Customer.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-06-25 16:01:35 2026-09-05 16:31:04 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:33:18 2026-09-04 16:33:18 attacker malicious-activity
Bruteforce login attacker Blocklist.de 2026-09-02 09:00:42 2026-09-03 09:00:43 attacker malicious-activity
HTTP Attacker Blocklist.de 2026-09-02 07:00:49 2026-09-03 07:00:59 attacker malicious-activity
HTTP Spammer StopForumSpam.com 2026-03-21 14:36:49 2026-07-21 09:15:22 malicious-activity
Malicious Host AbuseIPDB 2026-05-05 20:31:00 2026-05-06 16:23:03 malicious-activity
Suspicious Host AbuseIPDB 2026-03-17 00:01:27 2026-05-04 22:50:44 anomalous-activity
HTTP Spammer Sblam 2026-04-01 13:01:25 2026-04-06 13:02:36 malicious-activity
VPN IPWhois.io 2026-03-17 01:45:12 2026-03-17 01:45:12 anonymization

Tags

bot abuse apache ddos rfi attacker login bruteforce joomla wordpress

Whois information

AS name
AS206092 Private Customer
Registrant
Private Customer
City
Warsaw
Postal code
00-110
Country
PL — Poland 🇵🇱
First indexed
2026-03-17 01:45:12
Last updated
2026-09-05 16:31:04