← Back to Dashboard

213.175.186.85 Threat Intelligence Report

Risk Level: CRITICAL — 154 abuse reports from 8 sources

Threat Intelligence Summary

IP address 213.175.186.85 has been flagged in 154 abuse reports across 8 independent threat intelligence sources, resulting in a threat score of 100.0/100 (critical risk). The primary activity associated with this IP is aggregated threat, along with malicious, malware c2, malware infrastructure, port scan, rdp bruteforce, reconnaissance, reputation low.

This IP is geolocated in Lebanon (Beirut) and belongs to the network IncoNet Data Management sal (AS9051). Reports span from 2026-05-05 to 2026-09-19.

Assessment: With 154 abuse reports, 213.175.186.85 shows persistent malicious activity that has been flagged by multiple threat intelligence feeds. Systematic port scanning activity from this IP indicates active reconnaissance of internet-facing services, typically a precursor to targeted exploitation.

Data aggregated from 8 independent threat intelligence sources.

Geolocation

Country Lebanon
City Beirut
Region Beirut
Timezone Asia/Beirut

Threat Status

Overall Status Critical
Threat Score 100.0%
Report Count 154
Sources 8
First Seen 2026-05-05
Last Seen 2026-09-19
AI Analysis

Historical Threat Record

Status Known Historical Threat
Archived Reports 150
Peak Severity CRITICAL
History Span 2024-01-06 – 2026-05-31

🔒 The individual historical reports for this IP are part of premium intelligence. Free lookups show the last 90 days of live activity plus this summary.

Unlock full history →

Check IPs automatically with the WAYSCloud API

Free tier: 1,000 lookups/day. Get threat scores, geolocation, and abuse reports via REST API.

Explore the API →

See how we classify and verify threats →

Related Intelligence

Lebanon Threat Intelligence → AS9051 Network Intelligence → See all top malicious IPs → View latest attacks →
Learn about these threats: