138.197.165.254

Classification: Malicious

138.197.165.254 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-09. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker โ€” Seen launching attacks over the Internet.
  • Known scanner โ€” Seen scanning hosts over the Internet.
  • VPN node โ€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
VPN IPWhois.io 2026-09-09 10:47:53 2026-09-09 10:47:53 anonymization vpn
HTTP Scrapper AbuseIPDB 2026-09-02 13:33:40 2026-09-04 18:14:42 anomalous-activity attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-09-02 13:33:40 2026-09-04 18:14:42 attacker malicious-activity
Bruteforce AbuseIPDB 2026-09-02 13:33:40 2026-09-04 10:02:16 attacker malicious-activity
Port Scanner AbuseIPDB 2026-07-09 12:30:43 2026-09-04 10:02:16 anomalous-activity attacker malicious-activity reconnaissance
SSH Attacker AbuseIPDB 2026-09-03 22:00:49 2026-09-03 22:00:49 attacker malicious-activity
Hacking AbuseIPDB 2026-07-12 12:29:37 2026-09-03 22:00:49 attacker malicious-activity
HTTP bot Blocklist.de 2026-09-03 08:00:26 2026-09-03 08:00:26 attacker malicious-activity
DNS Compromise AbuseIPDB 2026-09-02 09:04:21 2026-09-02 09:04:21 compromised malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-07-14 11:10:28 2026-07-14 11:10:28 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-07-14 11:10:27 2026-07-14 11:10:27 malicious-activity
Malicious Host AbuseIPDB 2026-07-12 12:29:37 2026-07-12 12:29:37 compromised malicious-activity
Malicious Host CIArmy 2025-07-05 14:44:37 2025-11-25 17:36:19 malicious-activity
Suspicious Host AbuseIPDB 2025-07-07 00:08:24 2025-08-06 06:53:23 anomalous-activity
SSH Attacker Blocklist.de 2025-07-06 08:19:27 2025-07-07 08:05:23 malicious-activity
Mail Spammer Blocklist.de 2018-12-03 06:37:08 2018-12-04 06:55:44
HTTP Spammer StopForumSpam.com 2018-02-10 00:28:12 2018-02-10 00:28:12

Tags

bot abuse mail spam ssh bruteforce attacker

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2016-01-26 00:00:00
AS CIDR
138.197.160.0/20
CIDR
138.197.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
Toronto
State
NY
Postal code
M4R
Country
CA โ€” Canada ๐Ÿ‡จ๐Ÿ‡ฆ
Contact email
[email protected], [email protected]
First indexed
2018-02-10 00:28:12
Last updated
2026-09-09 10:47:55

Malicious IPs in the same CIDR

138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248