IP address


.15980.94.95.34
Shodan(more info)
Passive DNS
Tags:
IP blacklists
UCEPROTECT L1
80.94.95.34 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-09-20 07:45:00.682000
Was present on blacklist at: 2026-06-28 15:45, 2026-06-28 23:45, 2026-06-29 07:45, 2026-06-29 15:45, 2026-06-29 23:45, 2026-06-30 07:45, 2026-06-30 15:45, 2026-06-30 23:45, 2026-07-01 07:45, 2026-07-01 15:45, 2026-07-01 23:45, 2026-07-02 07:45, 2026-07-02 15:45, 2026-07-02 23:45, 2026-07-03 07:45, 2026-07-03 15:45, 2026-07-03 23:45, 2026-07-04 07:45, 2026-07-04 15:45, 2026-07-04 23:45, 2026-07-05 07:45, 2026-07-05 15:45, 2026-07-05 23:45, 2026-07-06 07:45, 2026-07-06 15:45, 2026-07-06 23:45, 2026-07-07 07:45, 2026-07-07 15:45, 2026-07-07 23:45, 2026-07-08 07:45, 2026-07-08 15:45, 2026-07-08 23:45, 2026-07-09 07:45, 2026-07-09 15:45, 2026-07-09 23:45, 2026-07-10 07:45, 2026-07-10 15:45, 2026-07-10 23:45, 2026-07-11 23:45, 2026-07-12 23:45, 2026-07-14 23:45, 2026-07-15 07:45, 2026-07-15 15:45, 2026-07-15 23:45, 2026-07-16 15:45, 2026-07-16 23:45, 2026-07-17 07:45, 2026-07-17 15:45, 2026-07-17 23:45, 2026-07-18 07:45, 2026-07-18 15:45, 2026-07-18 23:45, 2026-07-19 07:45, 2026-07-19 15:45, 2026-07-19 23:45, 2026-07-20 07:45, 2026-07-20 15:45, 2026-07-20 23:45, 2026-07-21 07:45, 2026-07-21 15:45, 2026-07-23 23:45, 2026-07-24 15:45, 2026-07-24 23:45, 2026-07-25 07:45, 2026-07-25 15:45, 2026-07-25 23:45, 2026-07-26 07:45, 2026-07-26 15:45, 2026-07-26 23:45, 2026-07-27 07:45, 2026-07-27 15:45, 2026-07-27 23:45, 2026-07-28 07:45, 2026-07-28 15:45, 2026-07-28 23:45, 2026-07-29 07:45, 2026-07-29 15:45, 2026-07-29 23:45, 2026-07-30 07:45, 2026-07-30 15:45, 2026-07-30 23:45, 2026-07-31 07:45, 2026-07-31 15:45, 2026-07-31 23:45, 2026-08-01 07:45, 2026-08-01 15:45, 2026-08-01 23:45, 2026-08-02 07:45, 2026-08-02 15:45, 2026-08-02 23:45, 2026-08-03 07:45, 2026-08-03 15:45, 2026-08-03 23:45, 2026-08-04 15:45, 2026-08-04 23:45, 2026-08-07 07:45, 2026-08-09 23:45, 2026-08-12 23:45, 2026-08-21 23:45, 2026-08-30 15:45, 2026-09-03 07:45, 2026-09-03 15:45, 2026-09-10 23:45, 2026-09-12 15:45, 2026-09-15 07:45, 2026-09-20 07:45
Spamhaus SBL
80.94.95.34 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-14 16:18:30.296000
Was present on blacklist at: 2026-06-22 16:18, 2026-06-29 16:18, 2026-07-06 16:18, 2026-07-13 16:18, 2026-07-20 16:18, 2026-07-27 16:18, 2026-08-03 16:18, 2026-08-10 16:18, 2026-08-17 16:18, 2026-08-24 16:18, 2026-08-31 16:18, 2026-09-07 16:26, 2026-09-14 16:18
Spamhaus DROP
80.94.95.34 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-14 16:18:30.296000
Was present on blacklist at: 2026-06-22 16:18, 2026-06-29 16:18, 2026-07-06 16:18, 2026-07-13 16:18, 2026-07-20 16:18, 2026-07-27 16:18, 2026-08-03 16:18, 2026-08-10 16:18, 2026-08-17 16:18, 2026-08-24 16:18, 2026-08-31 16:18, 2026-09-07 16:26, 2026-09-14 16:18
AbuseIPDB
80.94.95.34 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-07-28 04:00:00.653000
Was present on blacklist at: 2026-06-24 04:00, 2026-06-25 04:00, 2026-06-26 04:00, 2026-07-01 04:00, 2026-07-24 04:00, 2026-07-28 04:00
Echelon SSH connection attempt
80.94.95.34 is listed on the Echelon SSH connection attempt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: SSH connection attempt detected on port 22 or 2222
Type of feed: primary (feed detail page)

Last checked at: 2026-07-09 09:35:00.766000
Was present on blacklist at: 2026-07-02 09:35, 2026-07-03 09:35, 2026-07-04 09:35, 2026-07-05 09:35, 2026-07-06 09:35, 2026-07-07 09:35, 2026-07-08 09:35, 2026-07-09 09:35
Spamhaus XBL CBL
80.94.95.34 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-14 16:18:30.296000
Was present on blacklist at: 2026-06-22 16:18, 2026-06-29 16:18, 2026-07-20 16:18
Echelon port scan
80.94.95.34 is listed on the Echelon port scan blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning 5+ ports on target host
Type of feed: primary (feed detail page)

Last checked at: 2026-07-09 09:25:00.304000
Was present on blacklist at: 2026-07-03 09:25, 2026-07-04 09:25, 2026-07-05 09:25, 2026-07-06 09:25, 2026-07-07 09:25, 2026-07-08 09:25, 2026-07-09 09:25

Threat categories

TLRoleCategoryDetails
25 src

Warden events (69)
2026-08-01
ReconScanning (node.9c1411): 1
2026-07-31
ReconScanning (node.9c1411): 2
2026-07-30
ReconScanning (node.9c1411): 3
2026-07-29
ReconScanning (node.9c1411): 7
2026-07-28
AnomalyTraffic (node.6a1878): 1
ReconScanning (node.9c1411): 5
2026-07-27
AnomalyTraffic (node.6a1878): 1
ReconScanning (node.9c1411): 6
2026-07-26
AnomalyTraffic (node.6a1878): 1
2026-07-14
ReconScanning (node.9c1411): 1
2026-07-13
ReconScanning (node.9c1411): 2
2026-07-12
ReconScanning (node.9c1411): 1
2026-07-11
AnomalyTraffic (node.6a1878): 1
2026-07-09
AttemptLogin (node.7c8681): 1
ReconScanning (node.9c1411): 8
2026-07-08
ReconScanning (node.9c1411): 1
2026-07-07
AttemptLogin (node.ee25b8): 1
2026-07-05
AttemptLogin (node.e47683): 1
2026-07-04
AttemptLogin (node.e47683): 1
2026-07-03
ReconScanning (node.9c1411): 1
2026-07-02
ReconScanning (node.9c1411): 3
2026-07-01
ReconScanning (node.9c1411): 6
2026-06-30
ReconScanning (node.9c1411): 1
2026-06-28
ReconScanning (node.9c1411): 3
AnomalyTraffic (node.6a1878): 1
2026-06-27
ReconScanning (node.9c1411): 4
2026-06-26
ReconScanning (node.9c1411): 3
2026-06-24
ReconScanning (node.9c1411): 2
DShield reports (IP summary, reports)
2026-06-27
Number of reports: 28
Distinct targets: 16
2026-06-28
Number of reports: 24
Distinct targets: 15
2026-06-29
Number of reports: 66
Distinct targets: 46
2026-06-30
Number of reports: 66
Distinct targets: 46
2026-07-01
Number of reports: 17
Distinct targets: 9
2026-07-02
Number of reports: 11
Distinct targets: 9
2026-07-03
Number of reports: 22
Distinct targets: 11
2026-07-13
Number of reports: 69
Distinct targets: 45
OTX pulses
[6a201d9a478a18c5bf080afe] 2026-06-03 12:27:06.060000 | RDP honeypot logs for 2026/06/03
Author name:jnazario
Pulse modified:2026-06-03 12:27:06.060000
Indicator created:2026-06-03 12:27:06
Indicator role:None
Indicator title:
Indicator expiration:2026-07-03 12:00:00
[6a46577be350b02d0fd8231c] 2026-07-02 12:20:11.100000 | RDP honeypot logs for 2026/07/02
Author name:jnazario
Pulse modified:2026-07-02 12:20:11.100000
Indicator created:2026-07-02 12:20:12
Indicator role:None
Indicator title:
Indicator expiration:2026-08-01 12:00:00
[6a45060bb1c55702fde8b877] 2026-07-01 12:20:27.787000 | RDP honeypot logs for 2026/07/01
Author name:jnazario
Pulse modified:2026-07-01 12:20:27.787000
Indicator created:2026-07-01 12:20:28
Indicator role:None
Indicator title:
Indicator expiration:2026-07-31 12:00:00
[6a43b53f1509dcfe071ce4b9] 2026-06-30 12:23:27.353000 | RDP honeypot logs for 2026/06/30
Author name:jnazario
Pulse modified:2026-06-30 12:23:27.353000
Indicator created:2026-06-30 12:23:28
Indicator role:None
Indicator title:
Indicator expiration:2026-07-30 12:00:00
[6a4264423ba8b47e949e7939] 2026-06-29 12:25:38.443000 | RDP honeypot logs for 2026/06/29
Author name:jnazario
Pulse modified:2026-06-29 12:25:38.443000
Indicator created:2026-06-29 12:25:39
Indicator role:None
Indicator title:
Indicator expiration:2026-07-29 12:00:00
[6a41119c1d1373574ed6cf11] 2026-06-28 12:20:44.514000 | RDP honeypot logs for 2026/06/28
Author name:jnazario
Pulse modified:2026-06-28 12:20:44.514000
Indicator created:2026-06-28 12:20:45
Indicator role:None
Indicator title:
Indicator expiration:2026-07-28 12:00:00
[6a523522dccb99cc8dc4705e] 2026-07-11 12:20:50.734000 | RDP honeypot logs for 2026/07/11
Author name:jnazario
Pulse modified:2026-07-11 12:20:50.734000
Indicator created:2026-07-11 12:20:51
Indicator role:None
Indicator title:
Indicator expiration:2026-08-10 12:00:00
[6a4f9217ab023178b28fcd26] 2026-07-09 12:20:39.364000 | RDP honeypot logs for 2026/07/09
Author name:jnazario
Pulse modified:2026-07-09 12:20:39.364000
Indicator created:2026-07-09 12:20:40
Indicator role:None
Indicator title:
Indicator expiration:2026-08-08 12:00:00
[6a4b9db2bd11c792ee0b69c3] 2026-07-06 12:21:06.165000 | RDP honeypot logs for 2026/07/06
Author name:jnazario
Pulse modified:2026-07-06 12:21:06.165000
Indicator created:2026-07-06 12:21:06
Indicator role:None
Indicator title:
Indicator expiration:2026-08-05 12:00:00
[6a4a4d8ef7f598b67b017c50] 2026-07-05 12:26:54.445000 | RDP honeypot logs for 2026/07/05
Author name:jnazario
Pulse modified:2026-07-05 12:26:54.445000
Indicator created:2026-07-05 12:26:55
Indicator role:None
Indicator title:
Indicator expiration:2026-08-04 12:00:00
[6a47a96f16af7ec3ceebcb88] 2026-07-03 12:22:07.554000 | RDP honeypot logs for 2026/07/03
Author name:jnazario
Pulse modified:2026-07-03 12:22:07.554000
Indicator created:2026-07-03 12:22:08
Indicator role:None
Indicator title:
Indicator expiration:2026-08-02 12:00:00
[6a562982f802ef958c859c45] 2026-07-14 12:20:18.494000 | RDP honeypot logs for 2026/07/14
Author name:jnazario
Pulse modified:2026-07-14 12:20:18.494000
Indicator created:2026-07-14 12:20:19
Indicator role:None
Indicator title:
Indicator expiration:2026-08-13 12:00:00
[6a63587ffee530b79b5f91fa] 2026-07-24 12:20:15.620000 | RDP honeypot logs for 2026/07/24
Author name:jnazario
Pulse modified:2026-07-24 12:20:15.620000
Indicator created:2026-07-24 12:20:16
Indicator role:None
Indicator title:
Indicator expiration:2026-08-23 12:00:00
Origin AS
AS204428 - SS-Net
BGP Prefix
80.94.95.0/24
geo
Romania
🕑 Europe/Bucharest
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
80.94.92.0 - 80.94.95.255
last_activity
2026-08-01 04:58:36
last_warden_event
2026-08-01 04:58:36
rep
0.1591035847462855
reserved_range
0
Shodan's InternetDB
Open ports: 135, 3389
Tags: self-signed
CPEs:
ts_added
2026-04-13 16:18:23.055000
ts_last_update
2026-09-20 16:18:30.136000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses