IP address


.00080.94.95.152
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
80.94.95.152 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-20 03:08:20.182000
Was present on blacklist at: 2026-06-28 03:08, 2026-07-05 03:08, 2026-07-12 03:08, 2026-07-19 03:08, 2026-07-26 03:08, 2026-08-02 03:08, 2026-08-09 03:08, 2026-08-16 03:08, 2026-08-23 03:08, 2026-08-30 03:08, 2026-09-06 03:08, 2026-09-13 03:08, 2026-09-20 03:08
Spamhaus DROP
80.94.95.152 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-20 03:08:20.182000
Was present on blacklist at: 2026-06-28 03:08, 2026-07-05 03:08, 2026-07-12 03:08, 2026-07-19 03:08, 2026-07-26 03:08, 2026-08-02 03:08, 2026-08-09 03:08, 2026-08-16 03:08, 2026-08-23 03:08, 2026-08-30 03:08, 2026-09-06 03:08, 2026-09-13 03:08, 2026-09-20 03:08
AbuseIPDB
80.94.95.152 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-07-20 04:00:00.709000
Was present on blacklist at: 2026-06-23 04:00, 2026-06-24 04:00, 2026-07-19 04:00, 2026-07-20 04:00
UCEPROTECT L1
80.94.95.152 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-07-30 15:45:00.522000
Was present on blacklist at: 2026-06-23 07:45, 2026-06-23 15:45, 2026-06-23 23:45, 2026-06-24 07:45, 2026-06-24 15:45, 2026-06-24 23:45, 2026-06-25 07:45, 2026-06-25 15:45, 2026-06-25 23:45, 2026-06-26 07:45, 2026-06-26 15:45, 2026-06-26 23:45, 2026-06-27 07:45, 2026-06-27 15:45, 2026-06-27 23:45, 2026-06-28 07:45, 2026-07-18 07:45, 2026-07-18 15:45, 2026-07-19 15:45, 2026-07-20 07:45, 2026-07-20 15:45, 2026-07-20 23:45, 2026-07-21 07:45, 2026-07-21 15:45, 2026-07-21 23:45, 2026-07-22 07:45, 2026-07-22 15:45, 2026-07-22 23:45, 2026-07-23 07:45, 2026-07-23 15:45, 2026-07-24 07:45, 2026-07-24 15:45, 2026-07-24 23:45, 2026-07-25 07:45, 2026-07-25 15:45, 2026-07-25 23:45, 2026-07-26 07:45, 2026-07-26 15:45, 2026-07-26 23:45, 2026-07-27 07:45, 2026-07-27 15:45, 2026-07-27 23:45, 2026-07-28 07:45, 2026-07-28 15:45, 2026-07-28 23:45, 2026-07-29 07:45, 2026-07-29 15:45, 2026-07-29 23:45, 2026-07-30 07:45, 2026-07-30 15:45

Threat categories

TLRoleCategoryDetails
No threat category tags assigned

Warden events (61)
2026-07-27
ReconScanning (node.9c1411): 3
2026-07-26
ReconScanning (node.9c1411): 9
2026-07-25
ReconScanning (node.9c1411): 3
2026-07-23
ReconScanning (node.9c1411): 3
2026-07-22
ReconScanning (node.9c1411): 6
2026-07-21
ReconScanning (node.9c1411): 18
2026-07-20
ReconScanning (node.9c1411): 11
2026-07-19
AttemptLogin (node.b17ef8): 1
ReconScanning (node.9c1411): 2
2026-07-18
ReconScanning (node.9c1411): 4
2026-06-23
ReconScanning (node.9c1411): 1
DShield reports (IP summary, reports)
2026-07-20
Number of reports: 16
Distinct targets: 7
OTX pulses
[6a3a944d7f6deec6029fb45d] 2026-06-23 14:12:28.893000 | RDP honeypot logs for 2026/06/23
Author name:jnazario
Pulse modified:2026-06-23 14:12:28.893000
Indicator created:2026-06-23 14:12:29
Indicator role:bruteforce
Indicator title:
Indicator expiration:2026-07-23 00:00:00
[6a3a7aabdcdb1c7da7f46c02] 2026-06-23 12:23:07.296000 | RDP honeypot logs for 2026/06/23
Author name:jnazario
Pulse modified:2026-06-23 12:23:07.296000
Indicator created:2026-06-23 12:23:08
Indicator role:None
Indicator title:
Indicator expiration:2026-07-23 12:00:00
[6a3929390d765a82570a9753] 2026-06-22 12:23:21.230000 | RDP honeypot logs for 2026/06/22
Author name:jnazario
Pulse modified:2026-06-22 12:23:21.230000
Indicator created:2026-06-22 12:23:22
Indicator role:None
Indicator title:
Indicator expiration:2026-07-22 12:00:00
[6a62071070fef112fd09ebda] 2026-07-23 12:20:32.444000 | RDP honeypot logs for 2026/07/23
Author name:jnazario
Pulse modified:2026-07-23 12:20:32.444000
Indicator created:2026-07-23 12:20:33
Indicator role:None
Indicator title:
Indicator expiration:2026-08-22 12:00:00
[6a5e128c2bc21918e83956a0] 2026-07-20 12:20:28.516000 | RDP honeypot logs for 2026/07/20
Author name:jnazario
Pulse modified:2026-07-20 12:20:28.516000
Indicator created:2026-07-20 12:20:29
Indicator role:None
Indicator title:
Indicator expiration:2026-08-19 12:00:00
[6a5cc102f4b7deb8e7796c30] 2026-07-19 12:20:18.153000 | RDP honeypot logs for 2026/07/19
Author name:jnazario
Pulse modified:2026-07-19 12:20:18.153000
Indicator created:2026-07-19 12:20:18
Indicator role:None
Indicator title:
Indicator expiration:2026-08-18 12:00:00
[6a5b6f8063a9ab33a9e9cf3c] 2026-07-18 12:20:16.900000 | RDP honeypot logs for 2026/07/18
Author name:jnazario
Pulse modified:2026-07-18 12:20:16.900000
Indicator created:2026-07-18 12:20:17
Indicator role:None
Indicator title:
Indicator expiration:2026-08-17 12:00:00
Origin AS
AS204428 - SS-Net
BGP Prefix
80.94.95.0/24
geo
Romania
🕑 Europe/Bucharest
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
80.94.92.0 - 80.94.95.255
last_activity
2026-07-27 03:25:08
last_warden_event
2026-07-27 03:25:08
rep
0.0
reserved_range
0
ts_added
2026-06-21 03:08:10.119000
ts_last_update
2026-09-21 03:08:20.255000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses