IP address


.20644.220.185.37scanner-44-220-185-37.reposify.net
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
Spamhaus SBL CSS
44.220.185.37 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-05-16 09:02:50.787000
Was present on blacklist at: 2026-03-28 09:02, 2026-04-04 09:02, 2026-05-16 09:02
Turris greylist
44.220.185.37 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-03-02 22:15:00.153000
Was present on blacklist at: 2026-03-02 22:15
DataPlane SSH conn
44.220.185.37 is listed on the DataPlane SSH conn blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IP addresses that<br>has been seen initiating an unsolicited SSH connection to a remote host.
Type of feed: primary (feed detail page)

Last checked at: 2026-02-18 11:10:01.788000
Was present on blacklist at: 2026-02-16 15:10, 2026-02-16 19:10, 2026-02-16 23:10, 2026-02-17 03:10, 2026-02-17 07:10, 2026-02-17 11:10, 2026-02-17 15:10, 2026-02-17 19:10, 2026-02-17 23:10, 2026-02-18 03:10, 2026-02-18 07:10, 2026-02-18 11:10
LightScope
44.220.185.37 is listed on the LightScope blacklist.

Description: LightScope observes traffic sent to closed ports on production machines
Type of feed: primary (feed detail page)

Last checked at: 2026-03-04 10:30:01.231000
Was present on blacklist at: 2026-02-16 10:30, 2026-02-17 10:30, 2026-02-18 10:30, 2026-02-19 10:30, 2026-02-20 10:30, 2026-02-21 10:30, 2026-02-22 10:30, 2026-02-23 10:30, 2026-02-24 10:30, 2026-02-25 10:30, 2026-02-26 10:30, 2026-02-27 10:30, 2026-02-28 10:30, 2026-03-01 10:30, 2026-03-02 10:30, 2026-03-03 10:30, 2026-03-04 10:30
Echelon TLS/SSL crawler
44.220.185.37 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-05-08 09:40:01.394000
Was present on blacklist at: 2026-03-05 10:40, 2026-03-06 10:40, 2026-03-09 10:40, 2026-03-10 10:40, 2026-03-11 10:40, 2026-04-22 09:40, 2026-04-23 09:40, 2026-05-01 09:40, 2026-05-04 09:40, 2026-05-05 09:40, 2026-05-07 09:40, 2026-05-08 09:40

Threat categories

TLRoleCategoryDetails
25 src scan

Warden events (13)
2026-04-29
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-25
IntrusionUserCompromise (node.cfb4f7): 2
2026-04-15
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-11
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-07
IntrusionUserCompromise (node.cfb4f7): 2
2026-04-01
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-25
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-14
IntrusionUserCompromise (node.cfb4f7): 1
2026-03-06
IntrusionUserCompromise (node.cfb4f7): 2
2026-03-02
IntrusionUserCompromise (node.cfb4f7): 1
Origin AS
AS14618 - AMAZON-AES
BGP Prefix
44.192.0.0/11
geo
United States, Ashburn
🕑 America/New_York
hostname
scanner-44-220-185-37.reposify.net
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
44.192.0.0 - 44.255.255.255
last_activity
2026-04-29 02:11:17
last_warden_event
2026-04-29 02:11:17
rep
0.2062994740159002
reserved_range
0
ts_added
2025-12-13 09:02:41.966000
ts_last_update
2026-05-17 09:02:50.067000

Warden event timeline

DShield event timeline

Presence on blacklists