IP address


.000190.103.252.244244.252.103.190.unassigned.ridsa.com.ar
Shodan(more info)
Passive DNS
Tags: IP in hostname Residential proxy
IP blacklists
Spamhaus SBL CSS
190.103.252.244 was recently listed on the Spamhaus SBL CSS blacklist, but currently it is not.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-08-22 03:54:11.025000
Was present on blacklist at: 2026-08-08 03:54, 2026-08-15 03:54
Spamhaus XBL CBL
190.103.252.244 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-08-22 03:54:11.025000
Was present on blacklist at: 2026-08-08 03:54, 2026-08-15 03:54, 2026-08-22 03:54

Threat categories

TLRoleCategoryDetails
25 src scan port: 22, 23

Warden events (63)
2026-08-13
ReconScanning (node.ce2b59): 1
2026-08-12
ReconScanning (node.ce2b59): 26
2026-08-11
ReconScanning (node.ce2b59): 24
2026-08-09
ReconScanning (node.ce2b59): 6
2026-08-08
ReconScanning (node.ce2b59): 6
Residential proxy info (data provided by Layer3 Intel)
Last seen: 2026-08-24 00:54:03}
Percent days seen: 83 %
Networks: OXYLABS, NETNUT, INFATICA, DECODO, WEBSHARE, STRIKEPROXY, PROXYRACK, BOTTINGTOOLS, BIRDPROXIES, PROXYEMPIRE, 711PROXY, MASKIFY, LEMONBRIGHT, BYTEPROXIES, KOOKEY, EVOMI, PROXYWING, GONZOPROXY, THORDATA, BYTEFUL
Details: https://layer3intel.com/context/190.103.252.244
Origin AS
AS27983 -
BGP Prefix
190.103.252.0/24
geo
Argentina, Luque
🕑 America/Argentina/Cordoba
hostname
244.252.103.190.unassigned.ridsa.com.ar
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
190.103.240.0 - 190.103.255.255
last_activity
2026-08-13 00:00:45
last_warden_event
2026-08-13 00:00:45
rep
0.0001868017396484678
reserved_range
0
Shodan's InternetDB
Open ports: 22, 53, 80, 500
Tags: vpn
CPEs: cpe:/o:linux:linux_kernel, cpe:/a:apache:http_server, cpe:/o:debian:debian_linux, cpe:/a:openbsd:openssh:6.7p1
ts_added
2026-08-08 03:54:06.364000
ts_last_update
2026-08-26 03:54:10.185000

Warden event timeline

DShield event timeline

Presence on blacklists