IP address


.440209.99.189.124
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
Spamhaus SBL
209.99.189.124 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-23 09:05:20.375000
Was present on blacklist at: 2026-06-16 09:05, 2026-06-23 09:05
Spamhaus DROP
209.99.189.124 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-23 09:05:20.375000
Was present on blacklist at: 2026-06-16 09:05, 2026-06-23 09:05
Echelon SIP register scanner
209.99.189.124 is listed on the Echelon SIP register scanner blacklist.

Description: SIP VoIP registration scanning on port 5060
Type of feed: primary (feed detail page)

Last checked at: 2026-06-23 09:30:00.629000
Was present on blacklist at: 2026-06-16 09:30, 2026-06-17 09:30, 2026-06-18 09:30, 2026-06-19 09:30, 2026-06-20 09:30, 2026-06-21 09:30, 2026-06-22 09:30, 2026-06-23 09:30
AbuseIPDB
209.99.189.124 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-06-22 04:00:00.592000
Was present on blacklist at: 2026-06-22 04:00

Threat categories

TLRoleCategoryDetails
74 src scan port: 5060, 5090, 5091
38 src

Warden events (28)
2026-06-21
AnomalyTraffic (node.ce2b59): 2
ReconScanning (node.ce2b59): 2
2026-06-20
AnomalyTraffic (node.ce2b59): 2
ReconScanning (node.ce2b59): 1
2026-06-19
AnomalyTraffic (node.ce2b59): 2
ReconScanning (node.ce2b59): 1
2026-06-18
ReconScanning (node.ce2b59): 3
AnomalyTraffic (node.ce2b59): 8
2026-06-16
AnomalyTraffic (node.ce2b59): 5
ReconScanning (node.ce2b59): 2
DShield reports (IP summary, reports)
2026-06-16
Number of reports: 141
Distinct targets: 116
2026-06-17
Number of reports: 185
Distinct targets: 132
2026-06-18
Number of reports: 278
Distinct targets: 192
2026-06-19
Number of reports: 254
Distinct targets: 184
2026-06-20
Number of reports: 202
Distinct targets: 178
2026-06-21
Number of reports: 224
Distinct targets: 200
2026-06-22
Number of reports: 343
Distinct targets: 189
Origin AS
AS402253 - SKN-NETWORK-1
BGP Prefix
209.99.184.0/21
geo
Switzerland, Zurich
🕑 Europe/Zurich
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
209.99.128.0 - 209.99.191.255
last_activity
2026-06-21 17:21:54
last_warden_event
2026-06-21 17:21:54
rep
0.43994944904960476
reserved_range
0
Shodan's InternetDB
Open ports: 3389, 5357, 5985
Tags: self-signed
CPEs:
ts_added
2026-06-16 09:05:13.464000
ts_last_update
2026-06-23 09:30:06.349000

Warden event timeline

DShield event timeline

Presence on blacklists