167.172.42.230

Classification: Malicious

167.172.42.230 is a malicious IP address. Reported by 5 threat sources, last seen 2026-08-24. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malicious Host HoneyDB 2020-05-17 00:00:00 2026-08-24 00:00:00 attacker malicious-activity
Suspicious Host AbuseIPDB 2026-03-18 07:04:41 2026-03-18 07:04:41 anomalous-activity
SSH Attacker Blocklist.de 2025-12-24 07:08:56 2025-12-24 07:29:01 malicious-activity
Malicious Host AbuseIPDB 2025-12-23 20:11:59 2025-12-24 03:39:02 malicious-activity
Malicious Host CIArmy 2021-06-02 23:58:13 2021-06-02 23:58:13 malicious-activity
Mail Spammer Abuseat.org 2020-05-18 03:05:00 2020-05-18 03:05:00

Tags

ssh bruteforce bot

Whois information

AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.32.0/20
CIDR
167.172.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Avenue of the Americas, 10th Floor New York 10013 UNITED STATES
Country
US — United States 🇺🇸
First indexed
2020-05-18 03:04:57
Last updated
2026-08-25 22:01:48

Malicious IPs in the same CIDR

167.172.42.56 167.172.34.203 167.172.38.97 167.172.40.228 167.172.42.255 167.172.42.67 167.172.33.97 167.172.45.225 167.172.44.97 167.172.44.218 167.172.32.23 167.172.33.228 167.172.36.162 167.172.42.230 167.172.34.114 167.172.39.1 167.172.42.141