138.197.165.171

Classification: Malicious

138.197.165.171 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-12. Network: AS14061 Digitalocean, LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2023-03-13 05:55:08 2026-09-12 14:01:16 attacker malicious-activity
Bruteforce login attacker Blocklist.de 2026-08-12 09:00:35 2026-08-14 09:00:45 attacker malicious-activity
HTTP Attacker Blocklist.de 2026-08-12 07:00:38 2026-08-14 07:00:45 attacker malicious-activity
VPN IPWhois.io 2026-07-18 22:45:08 2026-07-18 22:45:08 anonymization vpn
Malicious Host AbuseIPDB 2026-05-03 02:05:56 2026-06-03 06:52:50 compromised malicious-activity
Proxy IPWhois.io 2026-05-17 08:15:30 2026-05-17 08:15:30 anonymization
SSH Attacker AbuseIPDB 2026-05-15 08:22:36 2026-05-17 07:57:57 malicious-activity
Bruteforce AbuseIPDB 2026-05-01 03:30:36 2026-05-17 07:57:57 malicious-activity
HTTP Attacker AbuseIPDB 2026-05-15 12:04:19 2026-05-17 06:58:03 malicious-activity
DDoS Attacker AbuseIPDB 2026-05-17 00:04:36 2026-05-17 00:04:36 malicious-activity
SQL Injection AbuseIPDB 2026-05-17 00:04:36 2026-05-17 00:04:36 malicious-activity
IMAP Attacker AbuseIPDB 2026-05-17 00:04:36 2026-05-17 00:04:36 malicious-activity
HTTP Scrapper AbuseIPDB 2026-05-17 00:04:36 2026-05-17 00:04:36 anomalous-activity
FTP Attacker AbuseIPDB 2026-05-16 07:01:36 2026-05-17 00:04:36 malicious-activity
Hacking AbuseIPDB 2026-04-30 16:48:33 2026-05-17 00:04:36 malicious-activity
IoT Attacker AbuseIPDB 2026-04-30 16:48:33 2026-05-17 00:04:36 malicious-activity
Port Scanner AbuseIPDB 2026-04-30 16:48:33 2026-05-17 00:04:36 anomalous-activity
Malicious Host HoneyDB 2023-03-12 00:00:00 2026-05-17 00:00:00 malicious-activity
Suspicious Host AbuseIPDB 2026-05-01 03:30:36 2026-05-03 03:23:19 anomalous-activity
Malicious Host CIArmy 2023-02-19 06:31:49 2023-04-09 07:06:58 malicious-activity
Mail Spammer Barracuda 2023-02-19 06:31:49 2023-02-19 06:31:49

Tags

ssh bruteforce bot apache ddos rfi attacker login joomla wordpress

Whois information

AS name
AS14061 Digitalocean, LLC
AS registry
arin
AS date
2016-01-26 00:00:00
AS CIDR
138.197.160.0/20
CIDR
138.197.0.0/16
Registrant
Digitalocean, LLC
Address
101 Ave of the Americas FL2
City
Toronto
State
NY
Postal code
M4S
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2023-02-19 06:31:49
Last updated
2026-09-12 14:01:16

Malicious IPs in the same CIDR

138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248