159.203.13.168
Classification: Malicious
159.203.13.168 is a malicious IP address. Reported by 8 threat sources, last seen 2026-09-05. Network: AS14061 Digitalocean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| DDoS Attacker | Blocklist.net.ua | 2026-03-19 12:50:59 | 2026-09-05 17:00:49 | attacker malicious-activity | |
| Empty reason | Blocklist.net.ua | 2026-09-04 17:04:21 | 2026-09-04 17:04:21 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-05-22 02:20:05 | 2026-05-22 02:20:05 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-05-22 02:20:02 | 2026-05-22 02:20:02 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2025-02-28 09:17:05 | 2026-05-21 02:23:03 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2025-02-04 23:16:59 | 2026-04-21 08:05:54 | compromised malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-02-28 03:00:31 | 2026-03-01 03:00:38 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-02-28 05:00:30 | 2026-02-28 05:00:30 | malicious-activity | |
| VPN | IPWhois.io | 2025-05-21 18:26:20 | 2026-02-20 03:31:11 | anonymization | |
| SSH Attacker | AbuseIPDB | 2025-02-04 22:03:16 | 2026-02-20 01:39:28 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2025-02-04 16:11:02 | 2026-02-20 01:39:28 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-02-04 22:51:03 | 2026-02-20 00:00:07 | anomalous-activity | |
| DDoS Attacker | AbuseIPDB | 2026-02-17 13:28:45 | 2026-02-19 21:59:20 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-02-03 22:17:22 | 2026-02-19 21:59:20 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2026-02-17 15:41:24 | 2026-02-19 21:11:47 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2025-02-02 18:56:34 | 2026-02-19 12:06:37 | anomalous-activity | |
| Hacking | AbuseIPDB | 2025-02-04 16:11:02 | 2026-02-19 09:35:40 | malicious-activity | |
| Mail Spammer | Barracuda | 2025-02-05 00:13:12 | 2025-06-15 02:38:01 | ||
| HTTP Spammer | StopForumSpam.com | 2025-04-13 04:51:13 | 2025-06-15 01:42:04 | malicious-activity | |
| Proxy | IPWhois.io | 2025-02-08 17:41:43 | 2025-04-13 04:57:17 | anonymization | |
| DDoS attack | AbuseIPDB | 2025-02-04 21:20:41 | 2025-03-23 03:20:12 | malicious-activity | |
| Malicious Host | CIArmy | 2025-02-08 17:41:41 | 2025-02-08 17:41:41 | malicious-activity | |
| IoT Attacker | AbuseIPDB | 2025-02-05 04:14:58 | 2025-02-05 04:14:58 | malicious-activity |
Tags
bot abuse apache ddos rfi attacker login bruteforce joomla wordpressWhois information
- AS name
- AS14061 Digitalocean, LLC
- AS registry
- arin
- AS date
- 2015-08-10 00:00:00
- AS CIDR
- 159.203.0.0/20
- CIDR
- 159.203.0.0/16
- Registrant
- Digitalocean, LLC
- Address
- 101 Ave of the Americas FL2
- City
- Toronto
- State
- NY
- Postal code
- M5H 2N2
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2025-02-05 00:13:10
- Last updated
- 2026-09-05 17:00:49
Malicious IPs in the same CIDR
159.203.12.188 159.203.10.155 159.203.12.100 159.203.10.37 159.203.10.114 159.203.10.168 159.203.6.67 159.203.7.225 159.203.13.23 159.203.1.70 159.203.14.97 159.203.6.112 159.203.13.83 159.203.3.27 159.203.3.90 159.203.15.202 159.203.13.168 159.203.7.251 159.203.6.171 159.203.2.208 159.203.1.197 159.203.13.64 159.203.0.16