159.65.216.232
Classification: Whitelisted
159.65.216.232 is a whitelisted (trusted) IP address. Reported by 11 threat sources, last seen 2026-07-25. Network: AS14061 Digitalocean, LLC.
Current activity
- Hosting provider — Shared hosting infrastructure.
MITRE ATT&CK associations
Malware families: EMOTET (S0367)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Hosting Provider | Maltiverse | 2026-07-25 09:18:02 | 2026-07-25 09:18:02 | benign hosting | |
| Phishing site | Hybrid-Analysis | 2020-03-02 07:15:05 | 2021-02-22 09:45:12 | ||
| Malicious Hostname | Cyber Threat Coalition | 2020-12-14 04:44:07 | 2021-02-22 09:18:04 | malicious-activity | |
| Phishing | Mr.Looquer | 2021-01-17 14:03:23 | 2021-02-22 07:01:08 | ||
| Phishing | Maltiverse | 2020-11-16 16:15:12 | 2021-02-22 04:41:39 | compromised | |
| Social Engineering | Maltiverse | 2020-11-16 16:15:12 | 2021-02-21 12:44:04 | malicious-activity | |
| Malicious url | Cyber Threat Coalition | 2020-12-14 15:29:40 | 2021-02-19 20:52:20 | malicious-activity | |
| Generic.Malware | Hybrid-Analysis | 2020-02-12 18:00:15 | 2021-02-17 10:30:21 | ||
| Magazine Luiza phishing | Antiphishing.com.ar | 2021-02-12 19:48:08 | 2021-02-12 19:48:08 | ||
| Phishing | Phishtank | 2020-02-01 08:40:59 | 2021-01-31 16:20:08 | compromised malicious-activity | |
| Web | Mr.Looquer | 2021-01-27 10:41:56 | 2021-01-27 10:41:56 | ||
| Facebook phishing | Antiphishing.com.ar | 2020-12-17 02:57:14 | 2021-01-08 12:52:59 | ||
| Social Engineering | Antiphishing.com.ar | 2020-08-03 11:09:36 | 2021-01-02 12:15:20 | malicious-activity | |
| Covid19 scam | Cyber Threat Coalition | 2020-11-20 20:05:54 | 2020-12-13 08:35:35 | malicious-activity | |
| Social Engineering | Phishtank | 2020-04-27 09:26:33 | 2020-12-08 08:21:17 | malicious-activity | |
| Phishing Facebook | Phishtank | 2020-12-03 19:20:22 | 2020-12-03 19:20:22 | compromised malicious-activity | |
| virut | Maltiverse Research Team | 2020-07-22 01:35:07 | 2020-11-14 01:26:27 | ||
| Phishing Office365 | OpenPhish | 2020-02-11 02:29:59 | 2020-10-24 04:00:58 | ||
| Social Engineering | OpenPhish | 2020-02-11 02:29:59 | 2020-10-24 04:00:58 | malicious-activity | |
| Trojan.Generic | Hybrid-Analysis | 2020-03-18 15:15:16 | 2020-10-21 19:00:51 | ||
| CIL.HeapOverride | Hybrid-Analysis | 2020-10-11 15:45:14 | 2020-10-11 15:45:14 | ||
| Phishing Generic/Spear Phishing | OpenPhish | 2020-09-11 06:48:55 | 2020-10-10 05:46:00 | ||
| paypal phishing | Antiphishing.com.ar | 2020-08-03 11:09:36 | 2020-10-07 11:23:41 | ||
| Phishing Facebook, Inc. | OpenPhish | 2020-09-06 06:44:28 | 2020-10-01 21:51:29 | ||
| Phishing WhatsApp | OpenPhish | 2020-09-20 06:20:40 | 2020-09-20 06:20:40 | ||
| Malware site | Hybrid-Analysis | 2020-06-08 22:45:33 | 2020-09-09 08:30:08 | ||
| Phishing PayPal Inc. | OpenPhish | 2020-08-11 06:04:33 | 2020-09-09 05:28:51 | ||
| Phishing Instagram | OpenPhish | 2020-08-17 11:44:41 | 2020-08-17 11:44:41 | ||
| Covid19 scam | DomainTools | 2020-04-19 18:18:52 | 2020-08-14 01:12:39 | malicious-activity | |
| Gen:Variant.Razy | Hybrid-Analysis | 2020-07-26 03:30:08 | 2020-07-26 03:30:08 | ||
| Malicious site | Hybrid-Analysis | 2020-04-01 11:15:06 | 2020-07-15 23:45:05 | ||
| Phishing BT Group plc | OpenPhish | 2020-04-09 02:19:16 | 2020-04-21 03:24:19 | ||
| Covid19 scam | CCN-CERT | 2020-04-13 15:13:54 | 2020-04-13 21:59:41 | malicious-activity | |
| IRS phishing | Antiphishing.com.ar | 2020-04-10 02:18:28 | 2020-04-10 02:18:28 | ||
| Malicious domain | Telefonica Peru | 2020-04-09 05:01:22 | 2020-04-09 05:08:33 | ||
| Emotet | Mr.Looquer | 2020-03-02 02:57:50 | 2020-03-02 02:57:50 | S0367 Emotet | |
| wetransfer phishing | Antiphishing.com.ar | 2020-02-29 01:46:34 | 2020-02-29 01:46:34 |
Tags
phishing sector:online services office365 malware binary sector:telecommunications bt group plc covid19 coronavirus scam c&c c2 dga sector:payment services paypal inc. sector:social networking instagram facebook, inc. sector:payment service generic/spear phishing whatsapp sector:online/cloud service fraud coinminerWhois information
- AS name
- AS14061 Digitalocean, LLC
- AS registry
- arin
- AS date
- 2017-10-24 00:00:00
- AS CIDR
- 159.65.216.0/21
- CIDR
- 159.65.0.0/16
- Registrant
- Digitalocean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- North Bergen
- State
- NJ
- Postal code
- 07047
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected]
- First indexed
- 2020-02-01 08:40:59
- Last updated
- 2026-07-25 09:18:02
Malicious IPs in the same CIDR
159.65.217.31 159.65.219.252 159.65.216.50 159.65.218.242 159.65.223.55 159.65.221.237 159.65.217.122 159.65.219.113