85.237.212.9
Classification: Malicious
85.237.212.9 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-05. Network: AS206092 Private Customer.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| DDoS Attacker | Blocklist.net.ua | 2026-06-25 16:01:35 | 2026-09-05 16:31:04 | attacker malicious-activity | |
| Empty reason | Blocklist.net.ua | 2026-09-04 16:33:18 | 2026-09-04 16:33:18 | attacker malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-09-02 09:00:42 | 2026-09-03 09:00:43 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-09-02 07:00:49 | 2026-09-03 07:00:59 | attacker malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2026-03-21 14:36:49 | 2026-07-21 09:15:22 | malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-05-05 20:31:00 | 2026-05-06 16:23:03 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2026-03-17 00:01:27 | 2026-05-04 22:50:44 | anomalous-activity | |
| HTTP Spammer | Sblam | 2026-04-01 13:01:25 | 2026-04-06 13:02:36 | malicious-activity | |
| VPN | IPWhois.io | 2026-03-17 01:45:12 | 2026-03-17 01:45:12 | anonymization |
Tags
bot abuse apache ddos rfi attacker login bruteforce joomla wordpressWhois information
- AS name
- AS206092 Private Customer
- Registrant
- Private Customer
- City
- Warsaw
- Postal code
- 00-110
- Country
- PL — Poland 🇵🇱
- First indexed
- 2026-03-17 01:45:12
- Last updated
- 2026-09-05 16:31:04