87.249.138.225

Classification: Malicious

87.249.138.225 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-28. Network: AS212238 CDNEXT NYC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
HTTP bot Blocklist.de 2026-08-28 08:01:17 2026-08-28 08:01:17 attacker malicious-activity
Proxy FireHOL 2023-01-01 05:36:09 2025-10-06 14:09:38 anonymization
Proxy IPWhois.io 2025-05-21 11:29:10 2025-06-14 20:52:12 anonymization
Mail Spammer Barracuda 2022-12-29 18:12:55 2025-06-14 20:52:12
HTTP Spammer StopForumSpam.com 2024-06-22 20:24:04 2025-06-14 20:52:11 malicious-activity
Anonymizer FireHol 2022-12-29 18:12:54 2022-12-30 05:46:10 anonymization

Tags

anonymization bot abuse attacker spam bruteforce

Whois information

AS name
AS212238 CDNEXT NYC
AS registry
ripencc
AS date
2005-08-30 00:00:00
AS CIDR
87.249.138.0/24
Registrant
CDNEXT NYC
City
New York
State
NY
Postal code
10000
Country
US — United States 🇺🇸
First indexed
2022-12-29 18:12:54
Last updated
2026-08-28 08:01:34

Malicious IPs in the same CIDR

87.249.138.233 87.249.138.39 87.249.138.237 87.249.138.166 87.249.138.76 87.249.138.17 87.249.138.81 87.249.138.106 87.249.138.234 87.249.138.113 87.249.138.119 87.249.138.123 87.249.138.1 87.249.138.84 87.249.138.50 87.249.138.199 87.249.138.116 87.249.138.225 87.249.138.48 87.249.138.90 87.249.138.246 87.249.138.229 87.249.138.7