138.197.149.131
Classification: Malicious
138.197.149.131 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-05. Network: AS14061 DigitalOcean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| DDoS Attacker | Blocklist.net.ua | 2026-08-28 16:35:07 | 2026-09-05 16:52:12 | attacker malicious-activity | |
| Empty reason | Blocklist.net.ua | 2026-09-04 16:55:21 | 2026-09-04 16:55:21 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2025-03-15 12:34:00 | 2026-09-01 07:00:11 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-08-21 06:19:14 | 2026-08-31 00:38:46 | anomalous-activity attacker malicious-activity reconnaissance | |
| Bruteforce | AbuseIPDB | 2025-03-08 08:17:15 | 2026-08-30 20:51:20 | attacker malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2025-03-15 13:34:44 | 2026-08-30 09:00:09 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-03-08 16:45:10 | 2026-08-29 13:08:18 | anomalous-activity attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-03-08 12:59:09 | 2026-08-29 13:08:18 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2025-03-08 08:50:07 | 2026-08-26 18:30:53 | attacker malicious-activity | |
| HTTP Spammer | GPF DNS Blocklist | 2025-03-24 08:15:22 | 2026-03-10 08:14:00 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-03-09 00:00:09 | 2025-09-10 15:50:42 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2025-03-10 04:19:52 | 2025-08-28 04:30:15 | compromised malicious-activity | |
| Proxy | IPWhois.io | 2025-06-08 14:49:12 | 2025-06-16 09:26:58 | anonymization | |
| HTTP Spammer | StopForumSpam.com | 2025-03-16 02:55:39 | 2025-06-11 20:43:57 | malicious-activity | |
| VPN | IPWhois.io | 2025-03-11 05:59:09 | 2025-03-25 01:23:04 | anonymization | |
| SSH Attacker | AbuseIPDB | 2025-03-08 08:17:15 | 2025-03-23 02:14:17 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2025-03-14 05:01:29 | 2025-03-18 20:01:31 | malicious-activity | |
| Malware Download | URLhaus Abuse.ch | 2022-04-28 07:15:27 | 2022-04-28 07:15:27 | malicious-activity |
Tags
malware_download apache ddos rfi attacker login bruteforce bot joomla wordpress abuseWhois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2016-01-26 00:00:00
- AS CIDR
- 138.197.144.0/20
- CIDR
- 138.197.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- Toronto
- State
- NY
- Postal code
- M4S
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2022-04-28 07:15:27
- Last updated
- 2026-09-05 16:52:12
Malicious IPs in the same CIDR
138.197.148.150 138.197.147.248 138.197.155.203 138.197.154.118 138.197.146.59 138.197.155.72 138.197.158.200 138.197.152.229 138.197.154.9 138.197.152.223 138.197.153.44 138.197.144.34 138.197.149.131 138.197.152.1 138.197.147.6 138.197.155.154 138.197.157.0 138.197.157.130 138.197.155.246 138.197.153.228 138.197.152.130 138.197.149.29 138.197.148.39 138.197.154.149 138.197.151.117