95.211.26.159
Classification: Malicious
95.211.26.159 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 2 threat sources, last seen 2026-09-04.
Current activity
- Known attacker — Seen launching attacks over the Internet.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Mail Spammer | Barracuda | 2022-05-09 19:18:43 | 2026-09-04 13:54:51 | attacker malicious-activity | |
| Cobalt Strike | ThreatFox Abuse.ch | 2022-05-09 19:18:41 | 2022-05-15 19:26:11 | malicious-activity | S0154 Cobalt Strike |
Tags
cobaltstrike leaseweb-nl-ams-01 netherlands port:80 agentemis beacon port:443Whois information
- AS name
- AS60781 LeaseWeb Netherlands B.V.
- AS registry
- ripencc
- AS date
- 2009-02-05 00:00:00
- AS CIDR
- 95.211.0.0/16
- CIDR
- 95.211.21.192/26, 95.211.22.0/23, 95.211.24.0/22, 95.211.28.0/26
- Registrant
- LeaseWeb Netherlands B.V.
- Address
- [email protected]. To ensure proper processing of your abuse notification, please visit the website www.leaseweb.com/abuse for notification requirements. All police and other government agency requests must be sent to [email protected].
- City
- Haarlem
- Postal code
- 2011 HL
- Country
- NL — Netherlands 🇳🇱
- First indexed
- 2022-05-09 19:18:41
- Last updated
- 2026-09-04 13:54:52
Malicious IPs in the same CIDR
95.211.120.98 95.211.194.14 95.211.210.72 95.211.19.179 95.211.211.182 95.211.26.159 95.211.172.88 95.211.203.214 95.211.195.196 95.211.243.182 95.211.149.153