87.249.138.225
Classification: Malicious
87.249.138.225 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-28. Network: AS212238 CDNEXT NYC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| HTTP bot | Blocklist.de | 2026-08-28 08:01:17 | 2026-08-28 08:01:17 | attacker malicious-activity | |
| Proxy | FireHOL | 2023-01-01 05:36:09 | 2025-10-06 14:09:38 | anonymization | |
| Proxy | IPWhois.io | 2025-05-21 11:29:10 | 2025-06-14 20:52:12 | anonymization | |
| Mail Spammer | Barracuda | 2022-12-29 18:12:55 | 2025-06-14 20:52:12 | ||
| HTTP Spammer | StopForumSpam.com | 2024-06-22 20:24:04 | 2025-06-14 20:52:11 | malicious-activity | |
| Anonymizer | FireHol | 2022-12-29 18:12:54 | 2022-12-30 05:46:10 | anonymization |
Tags
anonymization bot abuse attacker spam bruteforceWhois information
- AS name
- AS212238 CDNEXT NYC
- AS registry
- ripencc
- AS date
- 2005-08-30 00:00:00
- AS CIDR
- 87.249.138.0/24
- Registrant
- CDNEXT NYC
- City
- New York
- State
- NY
- Postal code
- 10000
- Country
- US — United States 🇺🇸
- First indexed
- 2022-12-29 18:12:54
- Last updated
- 2026-08-28 08:01:34
Malicious IPs in the same CIDR
87.249.138.233 87.249.138.39 87.249.138.237 87.249.138.166 87.249.138.76 87.249.138.17 87.249.138.81 87.249.138.106 87.249.138.234 87.249.138.113 87.249.138.119 87.249.138.123 87.249.138.1 87.249.138.84 87.249.138.50 87.249.138.199 87.249.138.116 87.249.138.225 87.249.138.48 87.249.138.90 87.249.138.246 87.249.138.229 87.249.138.7