138.197.165.171
Classification: Malicious
138.197.165.171 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-12. Network: AS14061 Digitalocean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- IoT threat — Seen attacking IoT devices.
- Open proxy — Provides anonymization that can hide an attacker.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SSH Attacker | Blocklist.de | 2023-03-13 05:55:08 | 2026-09-12 14:01:16 | attacker malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-08-12 09:00:35 | 2026-08-14 09:00:45 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-08-12 07:00:38 | 2026-08-14 07:00:45 | attacker malicious-activity | |
| VPN | IPWhois.io | 2026-07-18 22:45:08 | 2026-07-18 22:45:08 | anonymization vpn | |
| Malicious Host | AbuseIPDB | 2026-05-03 02:05:56 | 2026-06-03 06:52:50 | compromised malicious-activity | |
| Proxy | IPWhois.io | 2026-05-17 08:15:30 | 2026-05-17 08:15:30 | anonymization | |
| SSH Attacker | AbuseIPDB | 2026-05-15 08:22:36 | 2026-05-17 07:57:57 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-05-01 03:30:36 | 2026-05-17 07:57:57 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-05-15 12:04:19 | 2026-05-17 06:58:03 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-05-17 00:04:36 | 2026-05-17 00:04:36 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2026-05-17 00:04:36 | 2026-05-17 00:04:36 | malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2026-05-17 00:04:36 | 2026-05-17 00:04:36 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-05-17 00:04:36 | 2026-05-17 00:04:36 | anomalous-activity | |
| FTP Attacker | AbuseIPDB | 2026-05-16 07:01:36 | 2026-05-17 00:04:36 | malicious-activity | |
| Hacking | AbuseIPDB | 2026-04-30 16:48:33 | 2026-05-17 00:04:36 | malicious-activity | |
| IoT Attacker | AbuseIPDB | 2026-04-30 16:48:33 | 2026-05-17 00:04:36 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-04-30 16:48:33 | 2026-05-17 00:04:36 | anomalous-activity | |
| Malicious Host | HoneyDB | 2023-03-12 00:00:00 | 2026-05-17 00:00:00 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2026-05-01 03:30:36 | 2026-05-03 03:23:19 | anomalous-activity | |
| Malicious Host | CIArmy | 2023-02-19 06:31:49 | 2023-04-09 07:06:58 | malicious-activity | |
| Mail Spammer | Barracuda | 2023-02-19 06:31:49 | 2023-02-19 06:31:49 |
Tags
ssh bruteforce bot apache ddos rfi attacker login joomla wordpressWhois information
- AS name
- AS14061 Digitalocean, LLC
- AS registry
- arin
- AS date
- 2016-01-26 00:00:00
- AS CIDR
- 138.197.160.0/20
- CIDR
- 138.197.0.0/16
- Registrant
- Digitalocean, LLC
- Address
- 101 Ave of the Americas FL2
- City
- Toronto
- State
- NY
- Postal code
- M4S
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2023-02-19 06:31:49
- Last updated
- 2026-09-12 14:01:16
Malicious IPs in the same CIDR
138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248