IP address


.24472.221.88.20ip72-221-88-20.ri.ri.cox.net
Shodan(more info)
Passive DNS
Tags: IP in hostname Residential proxy
IP blacklists
Echelon SSH connection attempt
72.221.88.20 is listed on the Echelon SSH connection attempt blacklist.

Description: SSH connection attempt detected on port 22 or 2222
Type of feed: primary (feed detail page)

Last checked at: 2026-08-27 09:35:00.512000
Was present on blacklist at: 2026-08-21 09:35, 2026-08-22 09:35, 2026-08-23 09:35, 2026-08-24 09:35, 2026-08-25 09:35, 2026-08-26 09:35, 2026-08-27 09:35
AbuseIPDB
72.221.88.20 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-04 04:00:00.696000
Was present on blacklist at: 2026-09-04 04:00

Threat categories

TLRoleCategoryDetails
51 src scan port: 22, 23
25 src login protocol: ssh
port: 22, 2222
25 src

Warden events (259)
2026-09-04
ReconScanning (node.ce2b59): 8
2026-09-03
ReconScanning (node.ce2b59): 18
2026-09-02
ReconScanning (node.ce2b59): 5
2026-08-29
ReconScanning (node.ce2b59): 7
2026-08-28
ReconScanning (node.ce2b59): 4
2026-08-27
ReconScanning (node.ce2b59): 31
2026-08-26
ReconScanning (node.ce2b59): 10
2026-08-25
ReconScanning (node.ce2b59): 10
2026-08-24
ReconScanning (node.ce2b59): 6
2026-08-23
ReconScanning (node.ce2b59): 22
2026-08-22
ReconScanning (node.ce2b59): 5
2026-08-21
ReconScanning (node.ce2b59): 12
AttemptLogin (node.70e749): 2
2026-08-20
ReconScanning (node.ce2b59): 6
2026-08-19
ReconScanning (node.ce2b59): 5
2026-08-18
ReconScanning (node.ce2b59): 13
2026-08-17
ReconScanning (node.ce2b59): 29
2026-08-16
ReconScanning (node.ce2b59): 30
2026-08-15
ReconScanning (node.ce2b59): 25
2026-08-14
ReconScanning (node.ce2b59): 8
2026-08-12
ReconScanning (node.ce2b59): 2
2026-08-10
ReconScanning (node.ce2b59): 1
DShield reports (IP summary, reports)
2026-08-27
Number of reports: 12
Distinct targets: 4
Residential proxy info (data provided by Layer3 Intel)
Last seen: 2026-08-10 00:46:16}
Percent days seen: 53 %
Networks: BOTTINGTOOLS, 711PROXY, KOOKEY, THORDATA, AKE.NET, B2PROXY, YUMIPROXY, IPFLY, IPPEAK, MOMOPROXY
Details: https://layer3intel.com/context/72.221.88.20
Origin AS
AS22773 - ASN-CXA-ALL-CCI-22773-RDC
BGP Prefix
72.221.64.0/18
geo
United States, Glastonbury
🕑 America/New_York
hostname
ip72-221-88-20.ri.ri.cox.net
hostname_class
['isp', 'ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
72.192.0.0 - 72.223.255.255
last_activity
2026-09-04 11:28:33
last_warden_event
2026-09-04 11:28:33
rep
0.24399434195068248
reserved_range
0
ts_added
2026-08-10 23:47:10.734000
ts_last_update
2026-09-04 11:33:46.164000

Warden event timeline

DShield event timeline

Presence on blacklists