IP address


.388196.251.121.244
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
196.251.121.244 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-16 12:20:26.916000
Was present on blacklist at: 2026-09-16 12:20
Spamhaus DROP
196.251.121.244 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-16 12:20:26.916000
Was present on blacklist at: 2026-09-16 12:20
UCEPROTECT L1
196.251.121.244 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-09-19 23:45:00.805000
Was present on blacklist at: 2026-09-17 23:45, 2026-09-18 07:45, 2026-09-18 15:45, 2026-09-18 23:45, 2026-09-19 07:45, 2026-09-19 15:45, 2026-09-19 23:45
AbuseIPDB
196.251.121.244 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-20 04:00:00.576000
Was present on blacklist at: 2026-09-18 04:00, 2026-09-19 04:00, 2026-09-20 04:00

Threat categories

TLRoleCategoryDetails
68 src scan
36 src

Warden events (106)
2026-09-18
ReconScanning (node.4dc198): 20
2026-09-17
ReconScanning (node.4dc198): 6
ReconScanning (node.368407): 42
2026-09-16
ReconScanning (node.368407): 26
ReconScanning (node.4dc198): 12
DShield reports (IP summary, reports)
2026-09-16
Number of reports: 85
Distinct targets: 65
2026-09-17
Number of reports: 238
Distinct targets: 107
2026-09-18
Number of reports: 122
Distinct targets: 82
2026-09-19
Number of reports: 122
Distinct targets: 82
Origin AS
AS205759 - GHOSTYNETWORKS
BGP Prefix
196.251.121.0/24
geo
Seychelles
🕑 Indian/Mahe
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
196.251.64.0 - 196.251.127.255
last_activity
2026-09-18 16:07:50
last_warden_event
2026-09-18 16:07:50
rep
0.38841596431510206
reserved_range
0
ts_added
2026-09-16 12:20:26.740000
ts_last_update
2026-09-20 05:00:45.243000

Warden event timeline

DShield event timeline

Presence on blacklists