Is 85.217.140.31 malicious?

IP reputation report for 85.217.140.31: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.

85.217.140.31 is listed on 38 threat intelligence sources

Detected by 38 threat intelligence sources in the isMalicious dataset — review before trusting this IP.

Threat verdict

VerdictListed on blocklists

Appears on threat intelligence blocklists — treat with caution.

Blocklist detections38 sources
Categoriesattack, malware, phishing, suspicious, abuse, botnet, bruteforce, malicious, c2, attacks
Confidence score100/100

Aggregated confidence across the sources reporting this indicator.

Last updated2026-07-16

Network & location

LocationGravelines, Hauts-de-France, France
ISPModat B.V.
ASNAS209334 — MODAT-01, NL
Network85.217.140.0/24
CompanyModat B.V.
InfrastructureDatacenter, Proxy

Detections

  • FireHOL - Greensnowattack
  • Opendbl Net - Ipsum.listmalware
  • Romain Marcoux - Malicious IPsphishing
  • Greensnow - Attacks Multi-protocolsphishing
  • IPsum Level 2suspicious
  • IPsum Level 3suspicious
  • SMTP Greetattack
  • IPsum – malicious IP feedmalware
  • ThreatHive - Hive Blocklist
  • Borestad - AbuseIPDB Blocklist (1d)abuse
  • Malware-Filter - Botnet Filterbotnet
  • T145 - Black Mirror IPv4 Blocklistmalware
  • IPsum Level 1suspicious
  • IPsum Level 5suspicious
  • Malware-Filter - Botnet Filter IPsbotnet
  • FireHOL - Ciarmymalware
  • CINSSCORE Bad Guysmalware
  • Telnet Loginbruteforce
  • IPsum Level 4suspicious
  • Romain Marcoux - Malicious Outgoing IPsphishing
  • Telnet Bruteforce IPsbruteforce
  • IPsum Level 6suspicious
  • VNC RFBattack
  • Threatview IP Blocklistmalicious

+14 more sources in the full report.

Threat categories

Related malicious IPs on nearby networks