159.203.22.199
Classification: Malicious
159.203.22.199 is a malicious IP address. Reported by 8 threat sources, last seen 2026-09-02. Network: AS14061 Digitalocean, LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malicious Host | CIArmy | 2024-07-18 22:55:24 | 2026-09-02 20:02:46 | attacker malicious-activity | |
| Malicious Host | HoneyDB | 2026-08-21 00:00:00 | 2026-08-27 00:00:00 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-02-27 02:18:56 | 2026-08-20 09:12:55 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-02-27 02:18:53 | 2026-08-20 09:12:53 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-07-17 02:36:13 | 2026-02-26 07:03:50 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2024-07-21 00:14:08 | 2024-11-12 20:39:04 | compromised malicious-activity | |
| Port Scanner | AbuseIPDB | 2024-07-17 02:36:13 | 2024-10-10 10:20:04 | anomalous-activity | |
| SSH Attacker | AbuseIPDB | 2024-07-18 00:50:18 | 2024-10-08 17:36:45 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2024-07-17 19:56:57 | 2024-10-08 05:30:19 | malicious-activity | |
| Hacking | AbuseIPDB | 2024-07-17 19:56:57 | 2024-10-02 07:35:33 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2024-07-18 15:32:56 | 2024-10-01 06:18:05 | malicious-activity | |
| IoT Attacker | AbuseIPDB | 2024-09-29 09:57:16 | 2024-09-29 09:57:16 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2024-07-18 02:37:54 | 2024-09-29 09:57:16 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2023-11-29 02:01:42 | 2024-08-04 08:09:54 | malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2023-11-25 06:42:46 | 2024-05-24 08:42:47 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2024-01-02 06:58:58 | 2024-02-17 22:25:28 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2023-11-29 02:26:39 | 2023-12-24 02:23:15 | malicious-activity | |
| Mail Spammer | Abuseat.org | 2023-11-25 06:42:46 | 2023-11-25 06:42:46 |
Tags
abuse apache ddos rfi attacker login bruteforce bot joomla wordpressWhois information
- AS name
- AS14061 Digitalocean, LLC
- AS registry
- arin
- AS date
- 2015-08-10 00:00:00
- AS CIDR
- 159.203.16.0/20
- CIDR
- 159.203.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas FL2
- City
- Toronto
- State
- NY
- Postal code
- M5H 2N2
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2023-11-25 06:42:46
- Last updated
- 2026-09-02 20:02:46
Malicious IPs in the same CIDR
159.203.22.199 159.203.21.205 159.203.26.126 159.203.26.39 159.203.22.144 159.203.17.75 159.203.19.40 159.203.25.248 159.203.25.239 159.203.16.102 159.203.21.104 159.203.28.55 159.203.23.243 159.203.21.131 159.203.22.136