IP address


.271185.242.226.70security.criminalip.com
Shodan(more info)
Passive DNS
Tags: Research scanner Whitelisted Scanner
IP blacklists
AbuseIPDB
185.242.226.70 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-04-26 04:00:00.609000
Was present on blacklist at: 2026-04-16 04:00, 2026-04-17 04:00, 2026-04-18 04:00, 2026-04-19 04:00, 2026-04-22 04:00, 2026-04-26 04:00
DShield Block
185.242.226.70 is listed on the DShield Block blacklist.

Description: Recommended Block List by DShield.org. It summarizes the top 20 attacking<br>class C (/24) subnets over the last three days.
Type of feed: secondary (feed detail page)

Last checked at: 2026-04-28 04:50:00
Was present on blacklist at: 2026-04-16 04:50, 2026-04-21 04:50, 2026-04-22 04:50, 2026-04-28 04:50
Echelon TLS/SSL crawler
185.242.226.70 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-04-23 09:40:02.815000
Was present on blacklist at: 2026-04-19 09:40, 2026-04-20 09:40, 2026-04-21 09:40, 2026-04-22 09:40, 2026-04-23 09:40
Echelon web crawler
185.242.226.70 is listed on the Echelon web crawler blacklist.

Description: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-04-23 09:50:01.174000
Was present on blacklist at: 2026-04-19 09:50, 2026-04-20 09:50, 2026-04-21 09:50, 2026-04-22 09:50, 2026-04-23 09:50

Threat categories

TLRoleCategoryDetails
70 src scan port: 443
40 src

Warden events (44)
2026-04-26
ReconScanning (node.9c1411): 1
2026-04-25
AnomalyTraffic (node.6a1878): 2
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 3
2026-04-20
ReconScanning (node.4dc198): 1
ReconScanning (node.9c1411): 1
2026-04-19
ReconScanning (node.368407): 3
AnomalyTraffic (node.6a1878): 7
ReconScanning (node.4dc198): 5
2026-04-18
AnomalyTraffic (node.6a1878): 4
ReconScanning (node.4dc198): 2
ReconScanning (node.368407): 1
2026-04-17
AnomalyTraffic (node.6a1878): 2
ReconScanning (node.ce2b59): 2
ReconScanning (node.4dc198): 2
2026-04-16
ReconScanning (node.368407): 2
ReconScanning (node.9c1411): 1
2026-04-15
AnomalyTraffic (node.6a1878): 2
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 1
DShield reports (IP summary, reports)
2026-04-14
Number of reports: 13
Distinct targets: 8
2026-04-15
Number of reports: 13
Distinct targets: 8
2026-04-16
Number of reports: 24
Distinct targets: 16
2026-04-17
Number of reports: 44
Distinct targets: 27
2026-04-18
Number of reports: 44
Distinct targets: 27
2026-04-19
Number of reports: 25
Distinct targets: 15
2026-04-20
Number of reports: 24
Distinct targets: 14
2026-04-21
Number of reports: 47
Distinct targets: 25
2026-04-22
Number of reports: 10
Distinct targets: 7
2026-04-23
Number of reports: 130
Distinct targets: 9
2026-04-24
Number of reports: 43
Distinct targets: 35
2026-04-25
Number of reports: 52
Distinct targets: 33
2026-04-26
Number of reports: 15
Distinct targets: 12
2026-04-27
Number of reports: 15
Distinct targets: 12
Origin AS
AS202425 - INT-NETWORK
BGP Prefix
185.242.226.0/24
geo
United States
🕑 America/Chicago
hostname
security.criminalip.com
hostname_class
['research_scanner']
Address block ('inetnum' or 'NetRange' in whois database)
185.242.224.0 - 185.242.227.255
last_activity
2026-04-26 00:20:33
last_warden_event
2026-04-26 00:20:33
rep
0.2706088474818638
reserved_range
0
ts_added
2026-04-15 05:01:40.495000
ts_last_update
2026-04-28 05:03:01.574000

Warden event timeline

DShield event timeline

Presence on blacklists