159.203.25.248

Classification: Malicious

159.203.25.248 is a malicious IP address. Reported by 5 threat sources, last seen 2026-08-28. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-05-16 12:01:28 2026-08-28 16:43:05 attacker malicious-activity
VPN IPWhois.io 2026-08-15 22:52:50 2026-08-15 22:52:50 anonymization vpn
Malicious Host AbuseIPDB 2026-05-15 22:41:14 2026-06-07 22:56:28 malicious-activity
Bruteforce login attacker Blocklist.de 2026-05-30 04:00:23 2026-05-31 04:00:12 malicious-activity
HTTP Attacker Blocklist.de 2026-05-30 02:00:17 2026-05-31 02:00:11 malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2020-12-02 09:32:15 2020-12-07 19:36:16 malicious-activity
Malicious Host CIArmy 2020-12-01 12:44:04 2020-12-06 17:30:01 malicious-activity

Tags

abuse apache ddos rfi attacker login bruteforce bot joomla wordpress

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2015-08-10 00:00:00
AS CIDR
159.203.16.0/20
CIDR
159.203.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
Toronto
State
NY
Postal code
M4S
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2020-12-01 12:44:04
Last updated
2026-08-28 16:43:05

Malicious IPs in the same CIDR

159.203.25.239 159.203.22.199 159.203.16.102 159.203.21.205 159.203.26.126 159.203.26.39 159.203.22.144 159.203.17.75 159.203.19.40 159.203.25.248 159.203.21.104 159.203.28.55 159.203.23.243 159.203.21.131 159.203.22.136