138.197.164.127
Classification: Malicious
138.197.164.127 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-26. Network: AS14061 DigitalOcean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
- IoT threat — Seen attacking IoT devices.
- Open proxy — Provides anonymization that can hide an attacker.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| VPN | IPWhois.io | 2026-08-26 13:25:05 | 2026-08-26 13:25:05 | anonymization vpn | |
| Bruteforce | AbuseIPDB | 2026-07-13 21:43:30 | 2026-08-16 20:17:22 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-07-31 11:10:22 | 2026-08-13 17:44:52 | attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2026-07-19 13:16:47 | 2026-08-13 17:44:52 | iot malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-07-13 21:43:30 | 2026-08-13 17:44:52 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2026-07-13 00:31:15 | 2026-08-13 17:44:52 | attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-07-09 04:13:04 | 2026-08-13 17:44:52 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-07-03 08:53:21 | 2026-08-13 17:44:52 | anomalous-activity attacker malicious-activity reconnaissance | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2025-12-17 00:45:46 | 2026-08-11 09:11:34 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2025-12-17 00:45:37 | 2026-08-11 09:11:32 | attacker malicious-activity | |
| Malicious Host | CIArmy | 2022-12-28 06:46:47 | 2026-08-08 20:02:13 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-08-02 00:55:15 | 2026-08-05 09:57:18 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-07-14 16:46:36 | 2026-08-02 00:59:03 | anomalous-activity attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-07-17 15:38:01 | 2026-08-01 21:03:41 | attacker compromised malicious-activity | |
| HTTP bot | Blocklist.de | 2026-07-31 08:00:18 | 2026-07-31 08:00:18 | attacker malicious-activity | |
| Proxy | IPWhois.io | 2026-07-16 16:51:33 | 2026-07-16 16:51:33 | anonymization proxy | |
| Suspicious Host | AbuseIPDB | 2025-08-28 19:13:24 | 2025-08-28 19:13:24 | anomalous-activity | |
| Malicious Host | HoneyDB | 2023-01-04 00:00:00 | 2023-01-04 00:00:00 | malicious-activity |
Tags
attacker spam bruteforce botWhois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2016-01-26 00:00:00
- AS CIDR
- 138.197.160.0/20
- CIDR
- 138.197.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas FL2
- City
- Toronto
- State
- NY
- Postal code
- M4S
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2022-12-28 06:46:47
- Last updated
- 2026-08-26 13:25:07
Malicious IPs in the same CIDR
138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248