97.107.131.248
Classification: Malicious
97.107.131.248 is a malicious IP address. Reported by 5 threat sources, last seen 2026-08-22. Network: AS63949 Linode.
Current activity
- Known attacker β Seen launching attacks over the Internet.
- Known scanner β Seen scanning hosts over the Internet.
- IoT threat β Seen attacking IoT devices.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-05-19 03:13:54 | 2026-08-22 09:08:57 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-05-19 03:13:51 | 2026-08-22 09:08:56 | attacker malicious-activity | |
| Malicious Host | CIArmy | 2025-02-24 00:03:07 | 2026-08-19 20:01:18 | attacker malicious-activity | |
| Mail Spammer | Barracuda | 2025-01-06 08:24:04 | 2026-08-08 20:31:04 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2024-12-10 08:04:45 | 2026-08-08 15:45:18 | anomalous-activity attacker malicious-activity reconnaissance | |
| SIP Attacker | AbuseIPDB | 2026-07-02 16:56:09 | 2026-08-08 05:36:49 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2025-02-23 17:05:28 | 2026-08-07 05:50:03 | attacker compromised malicious-activity | |
| Bruteforce | AbuseIPDB | 2025-01-05 04:37:00 | 2026-08-07 05:50:03 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2024-12-10 08:04:45 | 2026-08-06 07:36:15 | attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-01-05 04:37:00 | 2026-08-03 09:58:12 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2025-01-05 04:37:00 | 2026-08-01 10:00:03 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-01-05 04:37:00 | 2026-07-31 10:57:49 | anomalous-activity attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2026-07-24 04:55:21 | 2026-07-24 04:55:21 | iot malicious-activity | |
| SSH Attacker | AbuseIPDB | 2025-01-05 04:37:00 | 2026-06-29 00:45:07 | attacker malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-01-06 03:13:59 | 2026-05-16 00:06:36 | anomalous-activity | |
| DDoS attack | AbuseIPDB | 2025-02-21 21:35:10 | 2025-03-22 15:16:50 | malicious-activity | |
| DNS Compromise | AbuseIPDB | 2025-03-19 02:37:48 | 2025-03-19 02:37:48 | compromised | |
| SSH Attacker | Blocklist.de | 2025-02-27 20:01:18 | 2025-02-27 20:01:18 | malicious-activity | |
| DNS Poisoning | AbuseIPDB | 2025-01-06 02:20:02 | 2025-01-06 02:20:02 | compromised |
Tags
ssh bruteforce botWhois information
- AS name
- AS63949 Linode
- AS registry
- arin
- AS date
- 2008-12-12 00:00:00
- AS CIDR
- 97.107.128.0/20
- CIDR
- 97.107.128.0/20
- Registrant
- Linode
- Address
- 145 Broadway
- City
- Morristown
- State
- NJ
- Postal code
- 07960
- Country
- US β United States πΊπΈ
- Contact email
- [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2025-01-06 08:24:02
- Last updated
- 2026-08-22 09:09:14
Malicious IPs in the same CIDR
97.107.129.244 97.107.131.17 97.107.140.120 97.107.141.150 97.107.133.213 97.107.130.61 97.107.138.210 97.107.130.146 97.107.142.235 97.107.136.12 97.107.129.125 97.107.137.243 97.107.131.248 97.107.134.117