159.89.229.96

Classification: Malicious

159.89.229.96 is a malicious IP address. Reported by 6 threat sources, last seen 2026-08-22. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Known scanner β€” Seen scanning hosts over the Internet.
  • IoT threat β€” Seen attacking IoT devices.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-07-15 11:12:24 2026-08-22 09:13:12 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-07-15 11:12:23 2026-08-22 09:13:11 attacker malicious-activity
Malicious Host CIArmy 2026-07-03 20:02:34 2026-08-15 20:01:51 attacker malicious-activity
Port Scanner AbuseIPDB 2026-07-03 07:33:43 2026-08-10 18:25:54 anomalous-activity attacker malicious-activity reconnaissance
Bruteforce AbuseIPDB 2026-07-09 03:00:12 2026-08-09 13:47:02 attacker malicious-activity
Hacking AbuseIPDB 2026-07-03 08:14:40 2026-08-09 13:47:02 attacker malicious-activity
Malicious Host AbuseIPDB 2026-07-03 08:14:40 2026-08-09 13:47:02 attacker compromised malicious-activity
HTTP Attacker AbuseIPDB 2026-07-12 09:18:44 2026-08-09 06:34:37 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-07-09 03:00:12 2026-07-28 21:27:10 anomalous-activity attacker malicious-activity
IoT Attacker AbuseIPDB 2026-07-19 13:07:57 2026-07-23 15:39:45 iot malicious-activity
SSH Attacker AbuseIPDB 2026-07-17 13:46:47 2026-07-17 13:46:47 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-07-14 03:09:27 2026-07-14 03:09:27 attacker malicious-activity
SQL Injection AbuseIPDB 2026-07-09 03:00:12 2026-07-09 03:00:12 attacker malicious-activity
Suspicious Host AbuseIPDB 2025-06-30 02:03:04 2025-07-01 00:26:58 anomalous-activity
Malicious host Darklist 2021-06-11 00:37:19 2021-10-11 09:25:09 malicious-activity
SSH Attacker Blocklist.de 2021-09-15 05:29:00 2021-09-15 05:29:00 malicious-activity
ET COMPROMISED Known Compromised or Hostile Host Traffic UDP Emerging Threats 2021-07-23 04:47:48 2021-08-17 04:58:08 malicious-activity
ET COMPROMISED Known Compromised or Hostile Host Traffic TCP Emerging Threats 2021-07-23 04:47:25 2021-08-17 04:58:06 malicious-activity
ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic Emerging Threats 2020-03-20 02:04:17 2020-04-05 01:49:04 anonymization
Anonymizer Maltiverse 2020-03-19 02:18:15 2020-03-19 02:18:15

Tags

anonymizer tor apache attacker script kiddies ssh bruteforce bot

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2017-07-07 00:00:00
AS CIDR
159.89.224.0/20
CIDR
159.89.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
North Bergen
State
NJ
Postal code
07047
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected], [email protected]
First indexed
2020-03-19 02:18:15
Last updated
2026-08-22 09:13:15

Malicious IPs in the same CIDR

159.89.237.78 159.89.231.100 159.89.230.182 159.89.225.170 159.89.225.201 159.89.229.13 159.89.239.246 159.89.227.187 159.89.235.158 159.89.229.96 159.89.235.42