159.89.140.103
Classification: Malicious
159.89.140.103 is a malicious IP address. Reported by 3 threat sources, last seen 2026-08-28. IoC context and downloadable threat intel on Maltiverse.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SSH Attacker | Blocklist.de | 2026-08-28 14:02:00 | 2026-08-28 14:02:00 | attacker malicious-activity | |
| ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic | Emerging Threats | 2018-07-04 07:48:47 | 2018-11-16 07:51:43 | ||
| ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic | Emerging Threats | 2018-07-03 07:43:38 | 2018-08-29 07:37:31 | ||
| Anonymizer | Maltiverse | 2018-06-30 08:18:04 | 2018-06-30 08:18:04 |
Tags
anonymizer tor ssh bruteforce botWhois information
- AS registry
- arin
- AS date
- 2017-07-07 00:00:00
- AS CIDR
- 159.89.128.0/20
- CIDR
- 159.89.0.0/16
- Registrant
- DigitalOcean, LLC
- Address
- 101 Ave of the Americas 10th Floor
- City
- New York
- State
- NY
- Postal code
- 10013
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2018-06-30 08:18:04
- Last updated
- 2026-08-28 14:02:00