IP address


--80.94.95.203
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
80.94.95.203 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-05-15 05:06:42.429000
Was present on blacklist at: 2024-04-03 05:05, 2024-04-10 05:08, 2024-04-17 05:06, 2024-04-24 05:14, 2024-05-01 05:09, 2024-05-08 05:06, 2024-05-15 05:06
Spamhaus DROP
80.94.95.203 is listed on the Spamhaus DROP blacklist.

Description: The Spamhaus DROP (Don't Route Or Peer) lists are advisory"drop all traffic" lists. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-05-15 05:06:42.429000
Was present on blacklist at: 2024-04-03 05:05, 2024-04-10 05:08, 2024-04-17 05:06, 2024-04-24 05:14, 2024-05-01 05:09, 2024-05-08 05:06, 2024-05-15 05:06
UCEPROTECT L1
80.94.95.203 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2024-05-15 15:45:00.904000
Was present on blacklist at: 2024-04-03 15:45, 2024-04-03 23:45, 2024-04-04 07:45, 2024-04-04 15:45, 2024-04-04 23:45, 2024-04-05 07:45, 2024-04-05 15:45, 2024-04-05 23:45, 2024-04-06 07:45, 2024-04-06 15:45, 2024-04-06 23:45, 2024-04-07 07:45, 2024-04-07 15:45, 2024-04-07 23:45, 2024-04-08 07:45, 2024-04-08 15:45, 2024-04-08 23:45, 2024-04-09 07:45, 2024-04-09 15:45, 2024-04-09 23:45, 2024-04-10 07:45, 2024-04-11 23:45, 2024-04-12 07:45, 2024-04-12 15:45, 2024-04-12 23:45, 2024-04-13 07:45, 2024-04-13 15:45, 2024-04-13 23:45, 2024-04-14 07:45, 2024-04-14 15:45, 2024-04-14 23:45, 2024-04-15 07:45, 2024-04-15 15:45, 2024-04-15 23:45, 2024-04-16 07:45, 2024-04-16 15:45, 2024-04-16 23:45, 2024-04-17 07:45, 2024-04-17 15:45, 2024-04-17 23:45, 2024-04-18 07:45, 2024-04-18 15:45, 2024-04-25 23:45, 2024-04-26 07:45, 2024-04-26 15:45, 2024-04-26 23:45, 2024-04-27 07:45, 2024-04-27 15:45, 2024-04-27 23:45, 2024-04-28 07:45, 2024-04-28 15:45, 2024-04-28 23:45, 2024-04-29 07:45, 2024-04-29 15:45, 2024-04-29 23:45, 2024-04-30 07:45, 2024-04-30 15:45, 2024-04-30 23:45, 2024-05-01 07:45, 2024-05-01 15:45, 2024-05-01 23:45, 2024-05-02 07:45, 2024-05-02 15:45, 2024-05-08 23:45, 2024-05-09 07:45, 2024-05-09 15:45, 2024-05-09 23:45, 2024-05-10 07:45, 2024-05-10 15:45, 2024-05-10 23:45, 2024-05-11 07:45, 2024-05-11 15:45, 2024-05-11 23:45, 2024-05-12 07:45, 2024-05-12 15:45, 2024-05-12 23:45, 2024-05-13 07:45, 2024-05-13 15:45, 2024-05-13 23:45, 2024-05-14 07:45, 2024-05-14 15:45, 2024-05-14 23:45, 2024-05-15 07:45, 2024-05-15 15:45
DShield Block
80.94.95.203 was recently listed on the DShield Block blacklist, but currently it is not.

Description: Recommended Block List by DShield.org. It summarizes the top 20 attacking<br>class C (/24) subnets over the last three days.
Type of feed: secondary (feed detail page)

Last checked at: 2024-05-18 04:50:00
Was present on blacklist at: 2024-04-16 04:50
Spamhaus XBL CBL
80.94.95.203 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-05-15 05:06:42.429000
Was present on blacklist at: 2024-05-15 05:06
DShield reports (IP summary, reports)
2024-04-02
Number of reports: 16
Distinct targets: 4
2024-04-03
Number of reports: 26
Distinct targets: 9
2024-04-08
Number of reports: 16
Distinct targets: 8
2024-04-09
Number of reports: 32
Distinct targets: 10
2024-04-10
Number of reports: 22
Distinct targets: 7
2024-04-11
Number of reports: 10
Distinct targets: 5
2024-04-14
Number of reports: 16
Distinct targets: 8
2024-04-15
Number of reports: 48
Distinct targets: 16
2024-05-02
Number of reports: 35
Distinct targets: 15
2024-05-09
Number of reports: 56
Distinct targets: 28
2024-05-11
Number of reports: 104
Distinct targets: 51
2024-05-13
Number of reports: 137
Distinct targets: 57
2024-05-14
Number of reports: 58
Distinct targets: 18
2024-05-15
Number of reports: 148
Distinct targets: 60
2024-05-16
Number of reports: 60
Distinct targets: 22
OTX pulses
[6646150ca0f22fda80788a1b] 2024-05-16 14:15:40.595000 | RDP honeypot logs for 2024/05/16
Author name:jnazario
Pulse modified:2024-05-16 14:15:40.595000
Indicator created:2024-05-16 14:15:41
Indicator role:None
Indicator title:
Indicator expiration:2024-06-15 14:00:00
Origin AS
AS204428 - SS-Net
BGP Prefix
80.94.95.0/24
geo
Romania
🕑 Europe/Bucharest
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
80.94.92.0 - 80.94.95.255
last_activity
2024-05-16 16:06:59.365000
reserved_range
0
Shodan's InternetDB
Open ports: 135, 137, 3389
Tags: self-signed
CPEs:
ts_added
2024-04-03 05:05:31.305000
ts_last_update
2024-05-18 05:06:03.240000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses