95.211.26.159

Classification: Malicious

95.211.26.159 is a malicious IP address. Linked to Cobalt Strike malware. Reported by 2 threat sources, last seen 2026-09-04.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mail Spammer Barracuda 2022-05-09 19:18:43 2026-09-04 13:54:51 attacker malicious-activity
Cobalt Strike ThreatFox Abuse.ch 2022-05-09 19:18:41 2022-05-15 19:26:11 malicious-activity S0154 Cobalt Strike

Tags

cobaltstrike leaseweb-nl-ams-01 netherlands port:80 agentemis beacon port:443

Whois information

AS name
AS60781 LeaseWeb Netherlands B.V.
AS registry
ripencc
AS date
2009-02-05 00:00:00
AS CIDR
95.211.0.0/16
CIDR
95.211.21.192/26, 95.211.22.0/23, 95.211.24.0/22, 95.211.28.0/26
Registrant
LeaseWeb Netherlands B.V.
Address
[email protected]. To ensure proper processing of your abuse notification, please visit the website www.leaseweb.com/abuse for notification requirements. All police and other government agency requests must be sent to [email protected].
City
Haarlem
Postal code
2011 HL
Country
NL — Netherlands 🇳🇱
First indexed
2022-05-09 19:18:41
Last updated
2026-09-04 13:54:52

Malicious IPs in the same CIDR

95.211.120.98 95.211.194.14 95.211.210.72 95.211.19.179 95.211.211.182 95.211.26.159 95.211.172.88 95.211.203.214 95.211.195.196 95.211.243.182 95.211.149.153