IP address


.108209.42.25.31katawaz.exchange
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
209.42.25.31 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-10-13 02:50:00.935000
Was present on blacklist at: 2025-08-16 02:50, 2025-08-17 02:50, 2025-08-18 02:50, 2025-08-19 02:50, 2025-08-20 02:50, 2025-08-21 02:50, 2025-08-22 02:50, 2025-08-23 02:50, 2025-08-24 02:50, 2025-08-26 02:50, 2025-08-29 02:50, 2025-08-30 02:50, 2025-08-31 02:50, 2025-09-02 02:50, 2025-09-03 02:50, 2025-09-04 02:50, 2025-09-05 02:50, 2025-09-06 02:50, 2025-09-07 02:50, 2025-09-08 02:50, 2025-09-09 02:50, 2025-09-10 02:50, 2025-09-12 02:50, 2025-09-13 02:50, 2025-09-14 02:50, 2025-09-15 02:50, 2025-09-16 02:50, 2025-09-18 02:50, 2025-09-19 02:50, 2025-09-20 02:50, 2025-09-21 02:50, 2025-09-22 02:50, 2025-09-23 02:50, 2025-09-24 02:50, 2025-09-25 02:50, 2025-09-26 02:50, 2025-09-27 02:50, 2025-09-28 02:50, 2025-09-29 02:50, 2025-10-04 02:50, 2025-10-05 02:50, 2025-10-06 02:50, 2025-10-07 02:50, 2025-10-08 02:50, 2025-10-09 02:50, 2025-10-10 02:50, 2025-10-11 02:50, 2025-10-13 02:50
Spamhaus SBL
209.42.25.31 was recently listed on the Spamhaus SBL blacklist, but currently it is not.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-10-11 03:10:07.498000
Was present on blacklist at: 2025-08-16 02:55, 2025-08-23 02:55, 2025-08-30 02:55
AbuseIPDB
209.42.25.31 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-09-22 04:00:00.726000
Was present on blacklist at: 2025-09-20 04:00, 2025-09-22 04:00
Warden events (66)
2025-10-08
ReconScanning (node.9c1411): 2
2025-10-06
ReconScanning (node.9c1411): 3
2025-10-05
ReconScanning (node.9c1411): 2
2025-10-03
ReconScanning (node.9c1411): 1
2025-10-02
ReconScanning (node.9c1411): 2
2025-10-01
ReconScanning (node.9c1411): 1
2025-09-29
ReconScanning (node.9c1411): 1
2025-09-25
ReconScanning (node.9c1411): 1
2025-09-23
ReconScanning (node.9c1411): 1
2025-09-20
ReconScanning (node.9c1411): 1
2025-09-17
ReconScanning (node.9c1411): 2
2025-09-15
ReconScanning (node.9c1411): 15
2025-09-14
ReconScanning (node.9c1411): 20
2025-09-10
ReconScanning (node.9c1411): 3
2025-09-09
ReconScanning (node.9c1411): 11
DShield reports (IP summary, reports)
2025-08-17
Number of reports: 18
Distinct targets: 18
2025-08-22
Number of reports: 26
Distinct targets: 20
2025-08-28
Number of reports: 16
Distinct targets: 11
2025-08-29
Number of reports: 10
Distinct targets: 7
2025-09-03
Number of reports: 11
Distinct targets: 7
2025-09-06
Number of reports: 13
Distinct targets: 11
2025-09-07
Number of reports: 12
Distinct targets: 8
2025-09-14
Number of reports: 13
Distinct targets: 8
2025-09-16
Number of reports: 11
Distinct targets: 7
2025-09-18
Number of reports: 12
Distinct targets: 7
2025-09-21
Number of reports: 13
Distinct targets: 8
2025-10-07
Number of reports: 15
Distinct targets: 6
2025-10-08
Number of reports: 15
Distinct targets: 6
Origin AS
AS36218 - RIPE-36218
BGP Prefix
209.42.25.0/24
geo
United Kingdom, Poplar
🕑 Europe/London
hostname
katawaz.exchange
Address block ('inetnum' or 'NetRange' in whois database)
209.42.16.0 - 209.42.31.255
last_activity
2025-10-08 09:12:46
last_warden_event
2025-10-08 09:12:46
rep
0.10773809523809524
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80, 443, 1433, 3389, 5985, 5986, 47001, 49152
Tags: self-signed, database
CPEs: cpe:/a:openbsd:openssh:for_Windows_9.5, cpe:/a:microsoft:internet_information_services:10.0, cpe:/o:microsoft:windows, cpe:/a:microsoft:sql_server:12.0.4100.0
ts_added
2025-08-16 02:55:06.083000
ts_last_update
2025-10-13 14:05:20.308000

Warden event timeline

DShield event timeline

Presence on blacklists