94.130.48.154

Classification: Whitelisted

94.130.48.154 is a whitelisted (trusted) IP address. Reported by 3 threat sources, last seen 2026-07-25. Network: AS24940 Hetzner Online GmbH.

Current activity

  • Hosting provider — Shared hosting infrastructure.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Hosting Provider Maltiverse 2026-07-25 17:16:08 2026-07-25 17:16:08 benign hosting
Generic.Malware Hybrid-Analysis 2018-05-24 12:30:35 2018-09-06 19:00:10
Gen:Variant.Zusy Hybrid-Analysis 2018-08-25 21:15:23 2018-08-25 21:15:23
Mining pool Telefonica CO SOC 2018-07-04 10:03:07 2018-08-18 09:21:39
MSIL_Bladabindi.AS.gen Hybrid-Analysis 2018-07-18 09:45:15 2018-07-18 09:45:16
Gen:Variant.Ursu Hybrid-Analysis 2018-04-17 09:30:38 2018-06-19 07:50:26
DeepScan:Generic.BitCoinMiner.3 Hybrid-Analysis 2018-05-31 08:45:47 2018-05-31 08:45:47
HEUR:RiskTool.Generic Hybrid-Analysis 2018-05-10 09:01:07 2018-05-10 09:01:07
Application.Bitcoinminer Hybrid-Analysis 2018-05-01 19:45:28 2018-05-01 19:45:28
RiskTool.Win64.BitCoinMiner Hybrid-Analysis 2018-04-09 17:30:27 2018-04-09 17:30:27
coinminer ,evasive ,miner Maltiverse 2018-03-15 21:30:48 2018-03-15 21:30:48
bundlore ,coinminer ,evasive ,miner ,pua Maltiverse 2018-03-15 17:02:04 2018-03-15 17:02:04
evasive Maltiverse 2018-03-13 06:15:25 2018-03-13 06:15:25
evasive ,exploit ,miner ,spectre Maltiverse 2018-03-03 17:45:48 2018-03-03 17:45:48
miner Maltiverse 2017-10-17 05:08:25 2018-02-28 17:02:21
coinminer,miner,pua Maltiverse 2018-02-14 12:25:22 2018-02-14 12:25:22
evasive,miner Maltiverse 2018-02-07 19:24:15 2018-02-07 19:24:15
backdoor,coinminer,miner Maltiverse 2018-02-02 22:18:21 2018-02-02 22:18:21
banker,dofoil,ramnit,sharik,smokeloader Maltiverse 2018-01-15 17:34:48 2018-01-15 17:34:48
miner,ransomware Maltiverse 2017-12-20 20:33:20 2017-12-20 20:33:20
autoit,miner Maltiverse 2017-12-15 14:06:04 2017-12-15 14:06:04
coinminer,miner,msil Maltiverse 2017-10-29 18:30:51 2017-10-29 18:30:51
coinminer Maltiverse 2017-10-20 21:15:26 2017-10-20 21:15:26
coinminer,miner Maltiverse 2017-10-16 10:31:55 2017-10-16 10:31:55

Tags

backdoor coinminer miner evasive pua exploit spectre bundlore bitcoin

Whois information

AS name
AS24940 Hetzner Online GmbH
AS registry
ripencc
AS date
2008-06-23 00:00:00
AS CIDR
94.130.0.0/16
CIDR
94.130.48.128/26
Registrant
Hetzner Online GmbH
Address
Hetzner Online GmbH Industriestrasse 25 D-91710 Gunzenhausen Germany
City
Falkenstein/Vogtl.
Postal code
08223
Country
DE — Germany 🇩🇪
Contact email
[email protected], [email protected]
First indexed
2017-10-16 10:31:55
Last updated
2026-07-25 17:16:08

Malicious IPs in the same CIDR

94.130.89.176 94.130.10.179 94.130.70.185 94.130.69.48 94.130.51.212 94.130.201.104 94.130.69.218 94.130.10.218 94.130.21.250 94.130.11.28 94.130.52.190 94.130.142.182 94.130.44.97 94.130.71.8 94.130.225.221 94.130.240.16 94.130.177.190 94.130.178.184