159.223.5.148
Classification: Malicious
159.223.5.148 is a malicious IP address. Linked to Quasarrat malware. Reported by 3 threat sources, last seen 2026-09-01. Network: AS14061 DigitalOcean, LLC.
Current activity
- Command & Control server — Used by cybercriminals to control victim computers.
MITRE ATT&CK associations
Malware families: QUASARRAT (S0262)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Quasar RAT | ThreatFox Abuse.ch | 2026-09-01 06:55:12 | 2026-09-01 07:25:05 | botnet malicious-activity | S0262 QuasarRAT |
| Malicious Host | CIArmy | 2021-12-22 02:26:51 | 2021-12-22 02:26:51 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2021-12-03 04:39:52 | 2021-12-03 04:39:52 | malicious-activity |
Tags
apache ddos rfi attacker cinarat quasarrat yggdrasil port:4782 quasar ratWhois information
- AS name
- AS14061 DigitalOcean, LLC
- AS registry
- arin
- AS date
- 2020-11-03 00:00:00
- AS CIDR
- 159.223.0.0/20
- CIDR
- 159.223.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- Amsterdam
- State
- NY
- Postal code
- 1012 AB
- Country
- NL — Netherlands 🇳🇱
- Contact email
- [email protected], [email protected]
- First indexed
- 2021-12-03 04:39:52
- Last updated
- 2026-09-01 10:10:27
Malicious IPs in the same CIDR
159.223.6.153 159.223.0.20 159.223.10.217 159.223.3.98 159.223.5.148 159.223.3.67 159.223.10.37 159.223.9.188 159.223.10.58 159.223.9.56 159.223.14.7