138.197.149.131

Classification: Malicious

138.197.149.131 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-05. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-08-28 16:35:07 2026-09-05 16:52:12 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:55:21 2026-09-04 16:55:21 attacker malicious-activity
HTTP Attacker Blocklist.de 2025-03-15 12:34:00 2026-09-01 07:00:11 attacker malicious-activity
Port Scanner AbuseIPDB 2026-08-21 06:19:14 2026-08-31 00:38:46 anomalous-activity attacker malicious-activity reconnaissance
Bruteforce AbuseIPDB 2025-03-08 08:17:15 2026-08-30 20:51:20 attacker malicious-activity
Bruteforce login attacker Blocklist.de 2025-03-15 13:34:44 2026-08-30 09:00:09 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2025-03-08 16:45:10 2026-08-29 13:08:18 anomalous-activity attacker malicious-activity
HTTP Attacker AbuseIPDB 2025-03-08 12:59:09 2026-08-29 13:08:18 attacker malicious-activity
Hacking AbuseIPDB 2025-03-08 08:50:07 2026-08-26 18:30:53 attacker malicious-activity
HTTP Spammer GPF DNS Blocklist 2025-03-24 08:15:22 2026-03-10 08:14:00 malicious-activity
Suspicious Host AbuseIPDB 2025-03-09 00:00:09 2025-09-10 15:50:42 anomalous-activity
Malicious Host AbuseIPDB 2025-03-10 04:19:52 2025-08-28 04:30:15 compromised malicious-activity
Proxy IPWhois.io 2025-06-08 14:49:12 2025-06-16 09:26:58 anonymization
HTTP Spammer StopForumSpam.com 2025-03-16 02:55:39 2025-06-11 20:43:57 malicious-activity
VPN IPWhois.io 2025-03-11 05:59:09 2025-03-25 01:23:04 anonymization
SSH Attacker AbuseIPDB 2025-03-08 08:17:15 2025-03-23 02:14:17 malicious-activity
DDoS attack AbuseIPDB 2025-03-14 05:01:29 2025-03-18 20:01:31 malicious-activity
Malware Download URLhaus Abuse.ch 2022-04-28 07:15:27 2022-04-28 07:15:27 malicious-activity

Tags

malware_download apache ddos rfi attacker login bruteforce bot joomla wordpress abuse

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2016-01-26 00:00:00
AS CIDR
138.197.144.0/20
CIDR
138.197.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
Toronto
State
NY
Postal code
M4S
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2022-04-28 07:15:27
Last updated
2026-09-05 16:52:12

Malicious IPs in the same CIDR

138.197.148.150 138.197.147.248 138.197.155.203 138.197.154.118 138.197.146.59 138.197.155.72 138.197.158.200 138.197.152.229 138.197.154.9 138.197.152.223 138.197.153.44 138.197.144.34 138.197.149.131 138.197.152.1 138.197.147.6 138.197.155.154 138.197.157.0 138.197.157.130 138.197.155.246 138.197.153.228 138.197.152.130 138.197.149.29 138.197.148.39 138.197.154.149 138.197.151.117