167.172.52.88

Classification: Malicious

167.172.52.88 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-10. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET COMPROMISED Known Compromised or Hostile Host Traffic UDP Emerging Threats 2026-09-03 10:01:14 2026-09-10 10:01:15 compromised malicious-activity
ET COMPROMISED Known Compromised or Hostile Host Traffic TCP Emerging Threats 2026-09-03 10:01:13 2026-09-10 10:01:14 compromised malicious-activity
SSH Attacker Blocklist.de 2026-09-02 14:00:22 2026-09-02 14:00:22 attacker malicious-activity
HTTP Spammer StopForumSpam.com 2020-08-12 04:19:02 2020-08-12 04:19:02

Tags

bot abuse ssh bruteforce

Whois information

AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.48.0/20
CIDR
167.172.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Avenue of the Americas, 10th Floor New York 10013 UNITED STATES
Country
GB — United Kingdom 🇬🇧
First indexed
2020-08-12 04:19:02
Last updated
2026-09-10 10:01:27

Malicious IPs in the same CIDR

167.172.52.88 167.172.51.40 167.172.49.228 167.172.59.207 167.172.52.252 167.172.54.184 167.172.51.43 167.172.48.211 167.172.59.85 167.172.63.151