159.89.140.103

Classification: Malicious

159.89.140.103 is a malicious IP address. Reported by 3 threat sources, last seen 2026-08-28. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2026-08-28 14:02:00 2026-08-28 14:02:00 attacker malicious-activity
ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic Emerging Threats 2018-07-04 07:48:47 2018-11-16 07:51:43
ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic Emerging Threats 2018-07-03 07:43:38 2018-08-29 07:37:31
Anonymizer Maltiverse 2018-06-30 08:18:04 2018-06-30 08:18:04

Tags

anonymizer tor ssh bruteforce bot

Whois information

AS registry
arin
AS date
2017-07-07 00:00:00
AS CIDR
159.89.128.0/20
CIDR
159.89.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
New York
State
NY
Postal code
10013
Country
CA — Canada 🇨🇦
Contact email
[email protected], [email protected]
First indexed
2018-06-30 08:18:04
Last updated
2026-08-28 14:02:00

Malicious IPs in the same CIDR

159.89.138.46 159.89.140.103