Is 176.65.139.115 malicious?
IP reputation report for 176.65.139.115: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.
176.65.139.115 is listed on 49 threat intelligence sources
Detected by 49 threat intelligence sources in the isMalicious dataset — review before trusting this IP.
Threat verdict
VerdictListed on blocklists
Appears on threat intelligence blocklists — treat with caution.
Blocklist detections49 sources
Categoriesphishing, malware, abuse, suspicious, bruteforce, attack, botnet, malicious, attacks, c2
Confidence score100/100
Aggregated confidence across the sources reporting this indicator.
First seen2026-06-14
Last updated2026-07-05
Network & location
LocationEygelshoven, Limburg, The Netherlands
ISPOffshore LC
ASNAS214472 — STORMINDUSTRIES Hosting Services, US
Network176.65.139.0/24
CompanyStorm Industries
InfrastructureDatacenter, Proxy
Security posture
Open ports21
Detections
- Urlhaus Abuse Ch - Text
- Duggytuxy - Blacklist Ips For Fortinet Firewall Aa.txt
- Romain Marcoux - Malicious Outgoing IPsphishing
- Romain Marcoux - Malicious IPsphishing
- URLHaus Malware URLsmalware
- Borestad - AbuseIPDB Blocklist (1d)abuse
- Data-Shield IPv4 Blocklistmalware
- IPsum Level 2suspicious
- IPsum – malicious IP feedmalware
- ThreatHive - Hive Blocklist
- Malware-Filter - URLhaus Domainsmalware
- IPsum Level 1suspicious
- Telnet Loginbruteforce
- USOM - Malicious URL List (Turkey CERT)malware
- Opendbl Net - Blocklistde All.listmalware
- Blocklist - All SSH attacks (48h)attack
- Blocklist - All Attacks (48h)attack
- Telnet Bruteforce IPsbruteforce
- ThreatFox Recent IOCsmalware
- Ultimate Hosts Blacklist - Blocklist.demalware
- ThreatFox IOC IPsmalware
- Opendbl Net - Ipsum.listmalware
- IPsum Level 3suspicious
- SSH Password Authbruteforce
+25 more sources in the full report.