167.172.138.48

Classification: Malicious

167.172.138.48 is a malicious IP address. Reported by 7 threat sources, last seen 2026-08-28. Network: AS14061 Digitalocean, LLC.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Open proxy β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2024-09-29 17:33:18 2026-08-28 16:45:27 attacker malicious-activity
Proxy IPWhois.io 2024-12-21 00:13:07 2026-08-02 12:37:21 anonymization proxy
Mail Spammer Barracuda 2026-08-02 12:37:21 2026-08-02 12:37:21 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-11-23 01:18:10 2026-05-08 16:15:14 anomalous-activity
Proxy FireHOL 2024-12-28 06:40:22 2025-10-06 18:30:03 anonymization
Malicious Host AbuseIPDB 2025-09-22 22:26:18 2025-09-28 15:43:05 malicious-activity
Bruteforce login attacker Blocklist.de 2025-09-20 08:05:00 2025-09-24 08:47:47 malicious-activity
HTTP Attacker Blocklist.de 2025-09-19 07:25:52 2025-09-24 08:09:43 malicious-activity
HTTP Spammer StopForumSpam.com 2024-12-01 11:34:20 2025-02-09 04:59:03 malicious-activity

Tags

abuse bot anonymization apache ddos rfi attacker login bruteforce joomla wordpress

Whois information

AS name
AS14061 Digitalocean, LLC
AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.128.0/20
Registrant
Digitalocean, LLC
City
North Bergen
State
NJ
Postal code
07047
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2024-09-29 17:33:18
Last updated
2026-08-28 16:45:27

Malicious IPs in the same CIDR

167.172.136.12 167.172.138.229 167.172.129.109 167.172.138.147 167.172.131.98 167.172.129.25 167.172.138.48 167.172.138.187 167.172.129.130 167.172.133.85