167.172.39.1

Classification: Malicious

167.172.39.1 is a malicious IP address. Reported by 5 threat sources, last seen 2026-08-11. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malicious Host CIArmy 2026-08-11 20:02:28 2026-08-11 20:02:28 attacker malicious-activity
Malicious Host AbuseIPDB 2026-02-17 19:07:49 2026-03-07 03:39:07 malicious-activity
SSH Attacker Blocklist.de 2026-03-02 10:04:53 2026-03-03 10:04:18 malicious-activity
Mail Spammer Abuseat.org 2020-11-30 04:57:03 2020-11-30 04:57:03
Malicious Host HoneyDB 2020-11-29 00:00:00 2020-11-29 00:00:00 malicious-activity

Tags

ssh bruteforce bot

Whois information

AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.32.0/20
Country
US — United States 🇺🇸
First indexed
2020-11-30 04:57:03
Last updated
2026-08-11 20:02:29

Malicious IPs in the same CIDR

167.172.42.230 167.172.34.114 167.172.42.56 167.172.42.141 167.172.34.203 167.172.38.97 167.172.40.228 167.172.42.255 167.172.42.67 167.172.45.225 167.172.33.97 167.172.44.97 167.172.44.218 167.172.32.23 167.172.33.228 167.172.36.162 167.172.39.1