138.68.108.72
Classification: Malicious
138.68.108.72 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-02. Network: AS14061 DigitalOcean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
- IoT threat — Seen attacking IoT devices.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| VPN | IPWhois.io | 2026-09-02 21:03:32 | 2026-09-02 21:03:32 | anonymization vpn | |
| HTTP Attacker | AbuseIPDB | 2026-08-29 16:55:55 | 2026-09-02 20:27:26 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-08-23 06:26:17 | 2026-09-02 20:27:26 | attacker malicious-activity | |
| Malicious Host | CIArmy | 2026-08-24 20:02:52 | 2026-09-02 20:02:24 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-08-23 06:26:17 | 2026-09-02 20:02:03 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-08-23 07:19:39 | 2026-09-02 13:45:40 | anomalous-activity attacker malicious-activity reconnaissance | |
| FTP Attacker | Blocklist.de | 2026-08-24 10:00:03 | 2026-09-02 10:00:02 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2026-08-23 08:44:53 | 2026-09-02 07:11:44 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-08-26 02:51:57 | 2026-09-02 05:52:37 | anomalous-activity attacker malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-08-23 12:50:04 | 2026-09-02 03:50:03 | attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2026-09-01 10:16:59 | 2026-09-01 10:16:59 | iot malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-08-25 09:11:54 | 2026-08-31 09:10:52 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-08-25 09:11:52 | 2026-08-31 09:10:51 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-08-23 10:32:29 | 2026-08-23 10:32:29 | attacker compromised malicious-activity | |
| ET COMPROMISED Known Compromised or Hostile Host Traffic UDP | Emerging Threats | 2021-02-09 10:39:02 | 2021-03-08 13:38:31 | malicious-activity | |
| ET COMPROMISED Known Compromised or Hostile Host Traffic TCP | Emerging Threats | 2021-02-09 10:38:59 | 2021-03-08 13:38:28 | malicious-activity | |
| SSH Attacker | Blocklist.de | 2021-02-05 09:51:13 | 2021-02-06 23:15:24 | malicious-activity | |
| SSH Attacker | Blocklist.net.ua | 2021-02-05 10:54:23 | 2021-02-06 02:28:58 | malicious-activity |
Tags
ssh bruteforce bot abuse attacker ftpWhois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2016-01-26 00:00:00
- AS CIDR
- 138.68.96.0/20
- CIDR
- 138.68.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- Frankfurt am Main
- State
- NY
- Postal code
- 60313
- Country
- DE — Germany 🇩🇪
- Contact email
- [email protected], [email protected]
- First indexed
- 2021-02-05 02:01:02
- Last updated
- 2026-09-02 21:03:34
Malicious IPs in the same CIDR
138.68.108.72 138.68.106.202 138.68.106.235 138.68.98.18 138.68.104.134 138.68.109.96 138.68.111.189 138.68.100.141