94.23.121.241

Classification: Malicious

94.23.121.241 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 3 threat sources, last seen 2026-08-18. Network: AS16276 OVH SAS.

Current activity

  • Command & Control server — Used by cybercriminals to control victim computers.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Cobalt Strike ThreatFox Abuse.ch 2024-03-22 13:20:10 2026-08-18 12:25:20 botnet malicious-activity S0154 Cobalt Strike
Malware Download URLhaus Abuse.ch 2024-08-06 20:21:36 2024-08-06 20:21:36 malicious-activity
Mail Spammer Abuseat.org 2024-03-22 13:20:12 2024-03-22 13:20:12

Tags

as16276 c2 censys cobaltstrike ovh port:63420 agentemis beacon cobeacon shodan port:7433

Whois information

AS name
AS16276 OVH SAS
AS registry
ripencc
AS date
2008-07-15 00:00:00
AS CIDR
94.23.0.0/16
CIDR
94.23.120.0/23
Registrant
OVH SAS
Address
New London House, 6 London Street EC3R 7LP, LONDON UK
City
Paris
Postal code
75004
Country
FR — France 🇫🇷
Contact email
[email protected]
First indexed
2024-03-22 13:20:10
Last updated
2026-08-18 14:44:11

Malicious IPs in the same CIDR

94.23.12.112 94.23.61.200 94.23.168.79 94.23.174.15 94.23.210.48 94.23.148.66 94.23.170.63 94.23.34.95 94.23.25.75 94.23.69.29 94.23.168.183 94.23.162.186 94.23.174.120 94.23.149.136 94.23.68.187 94.23.172.32 94.23.76.52 94.23.76.244 94.23.69.67 94.23.121.150 94.23.70.32 94.23.45.103 94.23.183.171 94.23.121.241