Is 176.65.139.115 malicious?

IP reputation report for 176.65.139.115: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.

176.65.139.115 is listed on 49 threat intelligence sources

Detected by 49 threat intelligence sources in the isMalicious dataset — review before trusting this IP.

Threat verdict

VerdictListed on blocklists

Appears on threat intelligence blocklists — treat with caution.

Blocklist detections49 sources
Categoriesphishing, malware, abuse, suspicious, bruteforce, attack, botnet, malicious, attacks, c2
Confidence score100/100

Aggregated confidence across the sources reporting this indicator.

First seen2026-06-14
Last updated2026-07-05

Network & location

LocationEygelshoven, Limburg, The Netherlands
ISPOffshore LC
ASNAS214472 — STORMINDUSTRIES Hosting Services, US
Network176.65.139.0/24
CompanyStorm Industries
InfrastructureDatacenter, Proxy

Security posture

Open ports21

Detections

  • Urlhaus Abuse Ch - Text
  • Duggytuxy - Blacklist Ips For Fortinet Firewall Aa.txt
  • Romain Marcoux - Malicious Outgoing IPsphishing
  • Romain Marcoux - Malicious IPsphishing
  • URLHaus Malware URLsmalware
  • Borestad - AbuseIPDB Blocklist (1d)abuse
  • Data-Shield IPv4 Blocklistmalware
  • IPsum Level 2suspicious
  • IPsum – malicious IP feedmalware
  • ThreatHive - Hive Blocklist
  • Malware-Filter - URLhaus Domainsmalware
  • IPsum Level 1suspicious
  • Telnet Loginbruteforce
  • USOM - Malicious URL List (Turkey CERT)malware
  • Opendbl Net - Blocklistde All.listmalware
  • Blocklist - All SSH attacks (48h)attack
  • Blocklist - All Attacks (48h)attack
  • Telnet Bruteforce IPsbruteforce
  • ThreatFox Recent IOCsmalware
  • Ultimate Hosts Blacklist - Blocklist.demalware
  • ThreatFox IOC IPsmalware
  • Opendbl Net - Ipsum.listmalware
  • IPsum Level 3suspicious
  • SSH Password Authbruteforce

+25 more sources in the full report.

Threat categories

Related malicious IPs on nearby networks