IP address


--45.146.130.131
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
45.146.130.131 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-10-10 00:22:45.970000
Was present on blacklist at: 2025-08-08 00:01, 2025-08-15 00:01, 2025-08-22 00:01, 2025-08-29 00:01, 2025-09-05 00:01, 2025-09-12 00:01, 2025-09-19 00:01, 2025-09-26 00:01, 2025-10-03 00:01, 2025-10-10 00:22
Spamhaus DROP
45.146.130.131 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-10-10 00:22:45.970000
Was present on blacklist at: 2025-08-08 00:01, 2025-08-15 00:01, 2025-08-22 00:01, 2025-08-29 00:01, 2025-09-05 00:01, 2025-09-12 00:01, 2025-09-19 00:01, 2025-09-26 00:01, 2025-10-03 00:01, 2025-10-10 00:22
OTX pulses
[68951749fda95619a21de94a] 2025-08-07 21:14:49.720000 | Odyssey Stealer Malware Attacks macOS Users
Author name:AlienVault
Pulse modified:2025-08-07 21:29:33.014000
Indicator created:2025-08-07 21:14:50
Indicator role:None
Indicator title:
Indicator expiration:2025-09-06 21:00:00
[68a8aa737add292d5ee2097f] 2025-08-22 17:35:47.118000 | Clickfix on macOS: AppleScript Stealer, Terminal Phishing, and C2 Infrastructure
Author name:AlienVault
Pulse modified:2025-08-25 11:04:29.670000
Indicator created:2025-08-22 17:35:47
Indicator role:None
Indicator title:
Indicator expiration:2025-09-21 17:00:00
[68e94967bcab143b278f0611] 2025-10-10 17:59:02.682000 | The ClickFix Factory: First Exposure of IUAM ClickFix Generator
Author name:AlienVault
Pulse modified:2025-10-13 07:31:52.092000
Indicator created:2025-10-10 17:59:05
Indicator role:None
Indicator title:
Indicator expiration:2025-11-09 17:00:00
Origin AS
AS213790 - LimitedNetwork-AS
BGP Prefix
45.146.130.0/24
geo
Iran
🕑 Asia/Tehran
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
45.146.128.0 - 45.146.131.255
last_activity
2025-10-13 11:05:59.363000
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80, 1080
Tags:
CPEs: cpe:/o:debian:debian_linux, cpe:/a:openbsd:openssh:9.2p1, cpe:/o:linux:linux_kernel
ts_added
2025-08-08 00:01:32.999000
ts_last_update
2025-10-14 00:13:21.111000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses