138.197.164.127

Classification: Malicious

138.197.164.127 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-26. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2026-08-26 13:25:05 2026-08-26 13:25:05 anonymization vpn
Bruteforce AbuseIPDB 2026-07-13 21:43:30 2026-08-16 20:17:22 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-07-31 11:10:22 2026-08-13 17:44:52 attacker malicious-activity
IoT Attacker AbuseIPDB 2026-07-19 13:16:47 2026-08-13 17:44:52 iot malicious-activity
DDoS Attacker AbuseIPDB 2026-07-13 21:43:30 2026-08-13 17:44:52 attacker malicious-activity
Hacking AbuseIPDB 2026-07-13 00:31:15 2026-08-13 17:44:52 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-07-09 04:13:04 2026-08-13 17:44:52 attacker malicious-activity
Port Scanner AbuseIPDB 2026-07-03 08:53:21 2026-08-13 17:44:52 anomalous-activity attacker malicious-activity reconnaissance
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2025-12-17 00:45:46 2026-08-11 09:11:34 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2025-12-17 00:45:37 2026-08-11 09:11:32 attacker malicious-activity
Malicious Host CIArmy 2022-12-28 06:46:47 2026-08-08 20:02:13 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-08-02 00:55:15 2026-08-05 09:57:18 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-07-14 16:46:36 2026-08-02 00:59:03 anomalous-activity attacker malicious-activity
Malicious Host AbuseIPDB 2026-07-17 15:38:01 2026-08-01 21:03:41 attacker compromised malicious-activity
HTTP bot Blocklist.de 2026-07-31 08:00:18 2026-07-31 08:00:18 attacker malicious-activity
Proxy IPWhois.io 2026-07-16 16:51:33 2026-07-16 16:51:33 anonymization proxy
Suspicious Host AbuseIPDB 2025-08-28 19:13:24 2025-08-28 19:13:24 anomalous-activity
Malicious Host HoneyDB 2023-01-04 00:00:00 2023-01-04 00:00:00 malicious-activity

Tags

attacker spam bruteforce bot

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2016-01-26 00:00:00
AS CIDR
138.197.160.0/20
CIDR
138.197.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas FL2
City
Toronto
State
NY
Postal code
M4S
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2022-12-28 06:46:47
Last updated
2026-08-26 13:25:07

Malicious IPs in the same CIDR

138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248