159.203.21.131

Classification: Malicious

159.203.21.131 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-10. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-01-27 07:22:07 2026-08-10 09:13:21 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-01-27 07:21:56 2026-08-10 09:13:19 attacker malicious-activity
Suspicious Host AbuseIPDB 2026-01-25 02:31:41 2026-02-08 23:45:56 anomalous-activity
Malicious Host CIArmy 2026-01-26 02:36:28 2026-01-26 02:36:28 malicious-activity
Malicious Host HoneyDB 2025-11-27 00:00:00 2025-11-27 00:00:00 malicious-activity
Bruteforce login attacker Blocklist.de 2023-11-17 02:27:14 2023-11-18 02:28:08 malicious-activity
HTTP Attacker Blocklist.de 2023-11-17 02:02:23 2023-11-18 02:03:33 malicious-activity
Mail Spammer Abuseat.org 2023-11-17 02:02:29 2023-11-17 02:02:29

Tags

apache ddos rfi attacker login bruteforce bot joomla wordpress

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2015-08-10 00:00:00
AS CIDR
159.203.16.0/20
CIDR
159.203.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas FL2
City
Toronto
State
NY
Postal code
M4S
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2023-11-17 02:02:23
Last updated
2026-08-12 08:45:49

Malicious IPs in the same CIDR

159.203.16.102 159.203.22.199 159.203.21.205 159.203.26.126 159.203.26.39 159.203.22.144 159.203.17.75 159.203.19.40 159.203.25.248 159.203.25.239 159.203.21.104 159.203.28.55 159.203.23.243 159.203.21.131 159.203.22.136