164.90.202.72

Classification: Malicious

164.90.202.72 is a malicious IP address. Reported by 6 threat sources, last seen 2026-09-12. Network: AS14061 DigitalOcean, LLC.

Current activity

  • Known attacker โ€” Seen launching attacks over the Internet.
  • Known scanner โ€” Seen scanning hosts over the Internet.
  • Open proxy โ€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2026-08-27 14:00:30 2026-09-12 14:01:47 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-11 17:06:24 2026-09-11 17:06:24 attacker malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-09-10 09:12:36 2026-09-11 09:13:00 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-09-10 09:12:34 2026-09-11 09:12:58 malicious-activity
Malicious Host CIArmy 2026-09-05 20:02:43 2026-09-10 20:03:36 attacker malicious-activity
Malicious Host HoneyDB 2026-09-10 00:00:00 2026-09-10 00:00:00 attacker malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2026-09-09 16:07:35 2026-09-09 16:07:35 attacker malicious-activity
Mail Spammer AbuseIPDB 2026-09-05 07:04:35 2026-09-07 22:53:56 attacker malicious-activity
Port Scanner AbuseIPDB 2026-08-27 08:54:11 2026-09-07 22:53:56 anomalous-activity attacker malicious-activity reconnaissance
Bruteforce AbuseIPDB 2026-08-27 08:53:38 2026-09-07 22:53:56 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-08-27 08:54:11 2026-09-07 21:40:20 attacker malicious-activity
SSH Attacker Blocklist.net.ua 2026-09-07 16:01:57 2026-09-07 16:01:57 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-09-03 01:02:40 2026-09-07 07:45:06 attacker malicious-activity
FTP Attacker AbuseIPDB 2026-08-27 11:46:11 2026-09-07 07:24:50 attacker malicious-activity
Phishing AbuseIPDB 2026-09-05 08:18:37 2026-09-07 06:52:37 malicious-activity phishing
IMAP Attacker AbuseIPDB 2026-09-05 06:59:28 2026-09-07 06:52:37 attacker malicious-activity
Hacking AbuseIPDB 2026-08-27 09:53:14 2026-09-07 06:52:37 attacker malicious-activity
Malicious Host AbuseIPDB 2026-09-04 16:33:49 2026-09-07 06:15:15 attacker compromised malicious-activity
HTTP Scrapper AbuseIPDB 2026-09-05 11:29:43 2026-09-06 22:09:56 anomalous-activity attacker malicious-activity
Proxy AbuseIPDB 2026-09-05 17:50:29 2026-09-05 17:50:29 anonymization proxy
DDoS Attacker AbuseIPDB 2026-08-27 09:34:27 2026-09-05 14:04:14 attacker malicious-activity
Bruteforce login attacker Blocklist.de 2024-06-07 03:10:56 2024-06-08 02:58:12 malicious-activity
HTTP Attacker Blocklist.de 2024-06-07 02:35:19 2024-06-08 02:21:40 malicious-activity

Tags

apache ddos rfi attacker login bruteforce bot joomla wordpress ssh abuse

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
2019-08-19 00:00:00
AS CIDR
164.90.192.0/20
CIDR
164.90.128.0/17
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas FL2
City
Amsterdam
State
NY
Postal code
1012 AB
Country
NL โ€” Netherlands ๐Ÿ‡ณ๐Ÿ‡ฑ
Contact email
[email protected], [email protected]
First indexed
2024-06-07 02:35:19
Last updated
2026-09-12 14:01:47

Malicious IPs in the same CIDR

164.90.202.72 164.90.192.205 164.90.201.255 164.90.202.142 164.90.196.149 164.90.202.229 164.90.202.191 164.90.194.73 164.90.193.9 164.90.207.199 164.90.203.145 164.90.195.221 164.90.202.39 164.90.198.204 164.90.197.189