167.172.42.56

Classification: Malicious

167.172.42.56 is a malicious IP address. Reported by 5 threat sources, last seen 2026-08-23. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malicious Host HoneyDB 2026-01-16 00:00:00 2026-08-23 00:00:00 attacker malicious-activity
Malicious Host AbuseIPDB 2026-01-17 07:07:59 2026-01-23 08:06:06 malicious-activity
Suspicious Host AbuseIPDB 2026-01-16 03:27:20 2026-01-16 03:27:20 anomalous-activity
Malicious Host CIArmy 2024-06-20 11:24:16 2024-06-20 11:24:16 malicious-activity
SSH Attacker Blocklist.de 2024-03-14 04:19:38 2024-03-16 04:43:09 malicious-activity
Mail Spammer Barracuda 2024-03-14 04:19:45 2024-03-14 04:19:45

Tags

ssh bruteforce bot

Whois information

AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.32.0/20
CIDR
167.172.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Avenue of the Americas, 10th Floor New York 10013 UNITED STATES
Country
US — United States 🇺🇸
First indexed
2024-03-14 04:19:38
Last updated
2026-08-23 22:02:13

Malicious IPs in the same CIDR

167.172.44.97 167.172.44.218 167.172.32.23 167.172.33.228 167.172.42.255 167.172.36.162 167.172.40.228 167.172.42.230 167.172.38.97 167.172.42.56 167.172.34.203 167.172.34.114 167.172.39.1 167.172.42.141 167.172.33.97 167.172.42.67 167.172.45.225