IP address


.025144.172.94.30
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
blocklist.de Apache
144.172.94.30 is listed on the blocklist.de Apache blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing attacks on the service<br>Apache, Apache-DDOS, RFI-Attacks.
Type of feed: primary (feed detail page)

Last checked at: 2025-09-28 04:05:05.375000
Was present on blacklist at: 2025-09-26 10:05, 2025-09-26 16:05, 2025-09-26 22:05, 2025-09-27 04:05, 2025-09-27 10:05, 2025-09-27 16:05, 2025-09-27 22:05, 2025-09-28 04:05
AbuseIPDB
144.172.94.30 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-10-02 04:00:00.775000
Was present on blacklist at: 2025-09-27 04:00, 2025-09-28 04:00, 2025-09-29 04:00, 2025-09-30 04:00, 2025-10-01 04:00, 2025-10-02 04:00
Turris greylist
144.172.94.30 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-10-02 21:15:00.157000
Was present on blacklist at: 2025-09-27 21:15, 2025-09-28 21:15, 2025-09-29 21:15, 2025-09-30 21:15, 2025-10-01 21:15, 2025-10-02 21:15
Spamhaus XBL CBL
144.172.94.30 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-10-10 08:46:52.514000
Was present on blacklist at: 2025-10-03 08:46
Warden events (1141)
2025-10-01
ReconScanning (node.4dc198): 167
AnomalyTraffic (node.ffe95c): 1
ReconScanning (node.368407): 5
2025-09-30
ReconScanning (node.4dc198): 270
ReconScanning (node.368407): 8
AnomalyTraffic (node.86dac8): 5
2025-09-29
ReconScanning (node.4dc198): 258
AnomalyTraffic (node.86dac8): 6
AnomalyTraffic (node.ffe95c): 5
ReconScanning (node.368407): 11
2025-09-28
ReconScanning (node.4dc198): 150
AnomalyTraffic (node.ffe95c): 12
ReconScanning (node.368407): 7
AnomalyTraffic (node.86dac8): 2
2025-09-27
ReconScanning (node.4dc198): 154
ReconScanning (node.368407): 2
AnomalyTraffic (node.ffe95c): 7
2025-09-26
ReconScanning (node.4dc198): 70
ReconScanning (node.368407): 1
DShield reports (IP summary, reports)
2025-09-26
Number of reports: 462
Distinct targets: 160
2025-09-27
Number of reports: 915
Distinct targets: 212
2025-09-28
Number of reports: 1530
Distinct targets: 271
2025-09-29
Number of reports: 1530
Distinct targets: 271
2025-09-30
Number of reports: 826
Distinct targets: 256
OTX pulses
[68d6874d831da4b2661d607a] 2025-09-26 12:30:05.230000 | Apache honeypot logs for 26/Sep/2025
Author name:jnazario
Pulse modified:2025-09-26 12:30:05.230000
Indicator created:2025-09-26 12:30:06
Indicator role:None
Indicator title:
Indicator expiration:2025-10-26 12:00:00
[68da7ae2d939640e7773438c] 2025-09-29 12:26:10.914000 | Apache honeypot logs for 29/Sep/2025
Author name:jnazario
Pulse modified:2025-09-29 12:26:10.914000
Indicator created:2025-09-29 12:26:11
Indicator role:None
Indicator title:
Indicator expiration:2025-10-29 12:00:00
[68dbcce20c41e232860b6e5b] 2025-09-30 12:28:18.920000 | Apache honeypot logs for 30/Sep/2025
Author name:jnazario
Pulse modified:2025-09-30 12:28:18.920000
Indicator created:2025-09-30 12:28:19
Indicator role:None
Indicator title:
Indicator expiration:2025-10-30 12:00:00
[68dd1e4ce3ee9bdedcc1472a] 2025-10-01 12:27:56.664000 | Apache honeypot logs for 01/Oct/2025
Author name:jnazario
Pulse modified:2025-10-01 12:27:56.664000
Indicator created:2025-10-01 12:27:57
Indicator role:None
Indicator title:
Indicator expiration:2025-10-31 12:00:00
Origin AS
AS14956 - ROUTERHOSTING
BGP Prefix
144.172.94.0/24
geo
United States, Ogden
🕑 America/Denver
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
144.172.64.0 - 144.172.127.255
last_activity
2025-10-01 16:28:01.045000
last_warden_event
2025-10-01 14:07:09
rep
0.025
reserved_range
0
ts_added
2025-09-26 08:46:46.719000
ts_last_update
2025-10-13 08:46:54.811000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses