159.89.115.108

Classification: Malicious

159.89.115.108 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-06. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Bruteforce login attacker Blocklist.de 2026-09-06 09:00:13 2026-09-06 09:00:13 attacker malicious-activity
HTTP Attacker Blocklist.de 2026-09-06 07:00:14 2026-09-06 07:00:14 attacker malicious-activity
SSH Attacker Blocklist.de 2020-08-26 03:19:49 2020-09-30 09:58:55
Unauthorized scanning of hosts Blocklist.net.ua 2020-08-31 05:14:26 2020-09-29 10:13:15
SIP Attacker Blocklist.de 2020-09-20 03:21:32 2020-09-28 09:52:53
Malicious Host CIArmy 2020-08-31 05:25:40 2020-09-22 03:51:36
SSH Attacker Telefonica CO SOC 2020-08-26 21:58:04 2020-09-19 09:58:08
Malicious Host HoneyDB 2020-09-03 00:00:00 2020-09-16 00:00:00
Malicious host Darklist 2020-09-01 05:43:02 2020-09-01 05:43:02

Tags

ssh bruteforce bot abuse sip attacker apache ddos rfi login joomla wordpress

Whois information

AS registry
arin
AS date
2017-07-07 00:00:00
AS CIDR
159.89.112.0/20
CIDR
159.89.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
New York
State
NY
Postal code
10013
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2020-08-26 03:19:49
Last updated
2026-09-06 09:00:13

Malicious IPs in the same CIDR

159.89.124.112 159.89.115.219 159.89.126.142 159.89.115.108 159.89.127.165 159.89.126.13 159.89.123.203 159.89.121.75 159.89.114.95 159.89.117.170 159.89.118.173 159.89.119.139 159.89.118.21 159.89.125.248 159.89.116.161 159.89.116.120 159.89.117.68 159.89.112.228 159.89.114.134 159.89.125.102 159.89.117.122 159.89.112.232 159.89.113.189 159.89.125.65 159.89.123.44