Is 158.94.211.95 malicious?

IP reputation report for 158.94.211.95: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.

158.94.211.95 is listed on 28 threat intelligence sources

Detected by 28 threat intelligence sources in the isMalicious dataset — review before trusting this IP.

Threat verdict

VerdictListed on blocklists

Appears on threat intelligence blocklists — treat with caution.

Blocklist detections28 sources
Categoriesabuse, spam, phishing, malware, suspicious, malicious, threat-intel, botnet, c2
Confidence score100/100

Aggregated confidence across the sources reporting this indicator.

First seen2026-05-07
Last updated2026-07-05

Detections

  • FireHOL - Firehol Abusers 30dabuse
  • FireHOL - Php Commenters 30dspam
  • Romain Marcoux - Malicious IPsphishing
  • Romain Marcoux - Malicious Outgoing IPsphishing
  • Bitwire - Outbound Blocklistmalware
  • Borestad - AbuseIPDB Blocklist (1d)abuse
  • IPsum Level 1suspicious
  • IPsum – malicious IP feedmalware
  • ThreatHive - Hive Blocklist
  • Urlhaus Abuse Ch - Text
  • URLHaus Malware URLsmalware
  • Malware-Filter - URLhaus Domainsmalware
  • Threatview URL Blocklistmalicious
  • ThreatFox Recent IOCsmalware
  • ThreatFox IOC IPsmalware
  • Abuse.ch ThreatFox - Recentmalware
  • AlienVault OTX - Subscribed Pulse Indicatorsthreat-intel
  • Threatview IP Blocklistmalicious
  • Malware-Filter - Botnet Filterbotnet
  • Malware-Filter - Botnet Filter IPsbotnet
  • HaGeZi TIF - Threat Intelligence Feed IPsmalware
  • ViriBack C2 Trackerc2
  • Bitwire - Inbound Blocklistmalware
  • FireHOL - Et Blockattack

+4 more sources in the full report.

Threat categories

Related malicious IPs on nearby networks