Is 91.239.157.187 malicious?

IP reputation report for 91.239.157.187: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.

91.239.157.187 is listed on 23 threat intelligence sources

Detected by 23 threat intelligence sources in the isMalicious dataset — review before trusting this IP.

Threat verdict

VerdictListed on blocklists

Appears on threat intelligence blocklists — treat with caution.

Blocklist detections23 sources
Categoriesabuse, phishing, malware, suspicious, bruteforce
Confidence score100/100

Aggregated confidence across the sources reporting this indicator.

First seen2026-05-17
Last updated2026-05-17

Network & location

LocationFrankfurt am Main, Hesse, Germany
ISPClouvider Limited

Detections

  • FireHOL - Firehol Abusers 30dabuse
  • FireHOL - Stopforumspamabuse
  • FireHOL - Stopforumspam 30dabuse
  • FireHOL - Stopforumspam 180dabuse
  • FireHOL - Stopforumspam 7dabuse
  • FireHOL - Stopforumspam 90dabuse
  • FireHOL - Stopforumspam 365dabuse
  • Romain Marcoux - Malicious IPsphishing
  • Sefinek - Malicious IP Addressesmalware
  • Bitwire - Inbound Blocklistmalware
  • Duggytuxy - Blacklist Ips For Fortinet Firewall Aa.txt
  • Borestad - AbuseIPDB Blocklist (1d)abuse
  • Data-Shield IPv4 Blocklistmalware
  • IPsum Level 1suspicious
  • IPsum – malicious IP feedmalware
  • ThreatHive - Hive Blocklist
  • T145 - Black Mirror IPv4 Blocklistmalware
  • Greensnow - Attacks Multi-protocolsphishing
  • IPsum Level 2suspicious
  • Telnet Loginbruteforce
  • bitwire‑it IP blocklist – bad IPs updated every 2hmalware
  • Borestad - AbuseIPDB Blocklist (30d)abuse
  • X4BNet - Datacenter IPv4 Rangesrisk

Threat categories

Related malicious IPs on nearby networks