209.97.138.100

Classification: Malicious

209.97.138.100 is a malicious IP address. Reported by 8 threat sources, last seen 2026-08-28. Network: AS14061 DigitalOcean, LLC.

Current activity

  • VPN node — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Aisuru ThreatFox Abuse.ch 2026-08-24 10:22:36 2026-08-28 14:25:05 malicious-activity
VPN IPWhois.io 2026-08-24 14:11:55 2026-08-24 14:11:55 anonymization vpn
Malicious Host AbuseIPDB 2026-02-23 20:15:26 2026-02-24 20:15:34 malicious-activity
Malicious Host HoneyDB 2026-02-23 00:00:00 2026-02-23 00:00:00 malicious-activity
Suspicious Host AbuseIPDB 2025-08-14 21:30:54 2025-08-19 22:45:36 anomalous-activity
Malicious Host CIArmy 2018-05-27 08:53:56 2025-08-19 15:10:46 malicious-activity
Malicious Host Alienvault Ip Reputation Database 2018-05-27 06:41:49 2018-06-22 06:29:47
SSH Attacker Blocklist.net.ua 2018-05-27 07:48:15 2018-05-27 07:48:15
SSH Attacker Blocklist.de 2018-05-27 07:41:13 2018-05-27 07:41:13

Tags

ssh bruteforce bot abuse aisuru port:8001 port:8443 c2 port:8080

Whois information

AS name
AS14061 DigitalOcean, LLC
AS registry
arin
AS date
1997-07-03 00:00:00
AS CIDR
209.97.128.0/20
CIDR
209.97.128.0/18
Registrant
DigitalOcean, LLC
Address
101 Ave of the Americas 10th Floor
City
London
State
NY
Postal code
WC2N 6
Country
GB — United Kingdom 🇬🇧
Contact email
[email protected], [email protected]
First indexed
2018-05-26 15:18:02
Last updated
2026-08-28 14:25:05

Malicious IPs in the same CIDR

209.97.137.101 209.97.141.149 209.97.135.233 209.97.141.194 209.97.136.89 209.97.138.100 209.97.140.46 209.97.138.46 209.97.142.124 209.97.133.170