138.197.165.254
Classification: Malicious
138.197.165.254 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-09. Network: AS14061 DigitalOcean, LLC.
Current activity
- Known attacker โ Seen launching attacks over the Internet.
- Known scanner โ Seen scanning hosts over the Internet.
- VPN node โ Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| VPN | IPWhois.io | 2026-09-09 10:47:53 | 2026-09-09 10:47:53 | anonymization vpn | |
| HTTP Scrapper | AbuseIPDB | 2026-09-02 13:33:40 | 2026-09-04 18:14:42 | anomalous-activity attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-09-02 13:33:40 | 2026-09-04 18:14:42 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-09-02 13:33:40 | 2026-09-04 10:02:16 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-07-09 12:30:43 | 2026-09-04 10:02:16 | anomalous-activity attacker malicious-activity reconnaissance | |
| SSH Attacker | AbuseIPDB | 2026-09-03 22:00:49 | 2026-09-03 22:00:49 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2026-07-12 12:29:37 | 2026-09-03 22:00:49 | attacker malicious-activity | |
| HTTP bot | Blocklist.de | 2026-09-03 08:00:26 | 2026-09-03 08:00:26 | attacker malicious-activity | |
| DNS Compromise | AbuseIPDB | 2026-09-02 09:04:21 | 2026-09-02 09:04:21 | compromised malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-07-14 11:10:28 | 2026-07-14 11:10:28 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-07-14 11:10:27 | 2026-07-14 11:10:27 | malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-07-12 12:29:37 | 2026-07-12 12:29:37 | compromised malicious-activity | |
| Malicious Host | CIArmy | 2025-07-05 14:44:37 | 2025-11-25 17:36:19 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-07-07 00:08:24 | 2025-08-06 06:53:23 | anomalous-activity | |
| SSH Attacker | Blocklist.de | 2025-07-06 08:19:27 | 2025-07-07 08:05:23 | malicious-activity | |
| Mail Spammer | Blocklist.de | 2018-12-03 06:37:08 | 2018-12-04 06:55:44 | ||
| HTTP Spammer | StopForumSpam.com | 2018-02-10 00:28:12 | 2018-02-10 00:28:12 |
Tags
bot abuse mail spam ssh bruteforce attackerWhois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2016-01-26 00:00:00
- AS CIDR
- 138.197.160.0/20
- CIDR
- 138.197.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- Toronto
- State
- NY
- Postal code
- M4R
- Country
- CA โ Canada ๐จ๐ฆ
- Contact email
- [email protected], [email protected]
- First indexed
- 2018-02-10 00:28:12
- Last updated
- 2026-09-09 10:47:55
Malicious IPs in the same CIDR
138.197.165.171 138.197.174.172 138.197.173.94 138.197.173.249 138.197.175.165 138.197.165.12 138.197.169.42 138.197.167.14 138.197.169.166 138.197.174.121 138.197.171.237 138.197.160.183 138.197.165.254 138.197.161.145 138.197.166.134 138.197.162.152 138.197.166.178 138.197.171.178 138.197.165.63 138.197.171.227 138.197.174.62 138.197.166.108 138.197.164.127 138.197.174.194 138.197.169.248