IP address


.15980.94.95.88
Shodan(more info)
Passive DNS
Tags:
IP blacklists
UCEPROTECT L1
80.94.95.88 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-09-20 07:45:00.682000
Was present on blacklist at: 2026-07-15 07:45, 2026-07-15 15:45, 2026-07-15 23:45, 2026-07-16 15:45, 2026-07-16 23:45, 2026-07-17 07:45, 2026-07-17 15:45, 2026-07-17 23:45, 2026-07-18 07:45, 2026-07-18 15:45, 2026-07-18 23:45, 2026-07-19 07:45, 2026-07-19 15:45, 2026-07-19 23:45, 2026-07-20 07:45, 2026-07-20 15:45, 2026-07-20 23:45, 2026-07-21 07:45, 2026-07-21 15:45, 2026-07-21 23:45, 2026-07-22 07:45, 2026-07-22 15:45, 2026-07-22 23:45, 2026-07-23 07:45, 2026-07-23 15:45, 2026-07-23 23:45, 2026-07-24 07:45, 2026-07-24 15:45, 2026-07-28 23:45, 2026-07-29 07:45, 2026-07-29 15:45, 2026-07-29 23:45, 2026-07-30 07:45, 2026-07-30 15:45, 2026-07-30 23:45, 2026-07-31 07:45, 2026-07-31 15:45, 2026-07-31 23:45, 2026-08-01 07:45, 2026-08-01 15:45, 2026-08-01 23:45, 2026-08-02 07:45, 2026-08-02 15:45, 2026-08-02 23:45, 2026-08-03 07:45, 2026-08-03 15:45, 2026-08-03 23:45, 2026-08-04 07:45, 2026-08-04 15:45, 2026-08-04 23:45, 2026-08-05 07:45, 2026-08-05 15:45, 2026-08-05 23:45, 2026-08-06 07:45, 2026-08-06 15:45, 2026-08-06 23:45, 2026-08-07 07:45, 2026-08-07 15:45, 2026-08-07 23:45, 2026-08-08 07:45, 2026-08-08 15:45, 2026-08-08 23:45, 2026-08-09 07:45, 2026-08-09 15:45, 2026-08-09 23:45, 2026-08-10 07:45, 2026-08-10 15:45, 2026-08-10 23:45, 2026-08-11 07:45, 2026-08-11 15:45, 2026-08-11 23:45, 2026-08-12 07:45, 2026-08-12 15:45, 2026-08-12 23:45, 2026-08-13 07:45, 2026-08-13 15:45, 2026-08-13 23:45, 2026-08-14 07:45, 2026-08-14 15:45, 2026-08-14 23:45, 2026-08-15 07:45, 2026-08-15 15:45, 2026-08-15 23:45, 2026-08-16 07:45, 2026-08-16 15:45, 2026-08-16 23:45, 2026-08-17 07:45, 2026-08-17 15:45, 2026-08-17 23:45, 2026-08-18 07:45, 2026-08-18 15:45, 2026-08-18 23:45, 2026-08-19 07:45, 2026-08-21 23:45, 2026-08-30 15:45, 2026-09-03 07:45, 2026-09-03 15:45, 2026-09-10 23:45, 2026-09-12 15:45, 2026-09-15 07:45, 2026-09-20 07:45
Spamhaus SBL
80.94.95.88 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-18 16:00:40.043000
Was present on blacklist at: 2026-06-26 16:00, 2026-07-03 16:00, 2026-07-10 16:00, 2026-07-17 16:00, 2026-07-24 16:00, 2026-07-31 16:00, 2026-08-07 16:00, 2026-08-14 16:00, 2026-08-21 16:00, 2026-08-28 16:00, 2026-09-04 16:00, 2026-09-11 16:00, 2026-09-18 16:00
Spamhaus DROP
80.94.95.88 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-18 16:00:40.043000
Was present on blacklist at: 2026-06-26 16:00, 2026-07-03 16:00, 2026-07-10 16:00, 2026-07-17 16:00, 2026-07-24 16:00, 2026-07-31 16:00, 2026-08-07 16:00, 2026-08-14 16:00, 2026-08-21 16:00, 2026-08-28 16:00, 2026-09-04 16:00, 2026-09-11 16:00, 2026-09-18 16:00
Echelon SSH connection attempt
80.94.95.88 is listed on the Echelon SSH connection attempt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: SSH connection attempt detected on port 22 or 2222
Type of feed: primary (feed detail page)

Last checked at: 2026-06-26 09:35:00.472000
Was present on blacklist at: 2026-06-23 09:35, 2026-06-24 09:35, 2026-06-25 09:35, 2026-06-26 09:35
Spamhaus XBL CBL
80.94.95.88 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-18 16:00:40.043000
Was present on blacklist at: 2026-07-17 16:00, 2026-08-07 16:00, 2026-08-14 16:00
Echelon TLS/SSL crawler
80.94.95.88 is listed on the Echelon TLS/SSL crawler blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-08-19 09:40:00.505000
Was present on blacklist at: 2026-08-13 09:40, 2026-08-14 09:40, 2026-08-15 09:40, 2026-08-16 09:40, 2026-08-17 09:40, 2026-08-18 09:40, 2026-08-19 09:40

Threat categories

TLRoleCategoryDetails
25 src

Warden events (53)
2026-08-12
ReconScanning (node.9c1411): 1
2026-08-11
ReconScanning (node.9c1411): 3
2026-08-09
ReconScanning (node.ce2b59): 2
2026-08-04
ReconScanning (node.9c1411): 2
2026-08-03
ReconScanning (node.9c1411): 5
2026-08-02
ReconScanning (node.9c1411): 10
2026-08-01
ReconScanning (node.9c1411): 11
2026-07-29
AnomalyTraffic (node.6a1878): 1
2026-07-17
ReconScanning (node.9c1411): 9
2026-07-16
AnomalyTraffic (node.6a1878): 1
ReconScanning (node.9c1411): 2
2026-07-15
ReconScanning (node.9c1411): 6
DShield reports (IP summary, reports)
2026-08-09
Number of reports: 29
Distinct targets: 17
2026-08-10
Number of reports: 29
Distinct targets: 17
OTX pulses
[6a08623258558e44045faac9] 2026-05-16 12:25:22.700000 | RDP honeypot logs for 2026/05/16
Author name:jnazario
Pulse modified:2026-05-16 12:25:22.700000
Indicator created:2026-05-16 12:25:23
Indicator role:None
Indicator title:
Indicator expiration:2026-06-15 12:00:00
[6a58cc7f4a9cd9610e693318] 2026-07-16 12:20:15.141000 | RDP honeypot logs for 2026/07/16
Author name:jnazario
Pulse modified:2026-07-16 12:20:15.141000
Indicator created:2026-07-16 12:20:16
Indicator role:None
Indicator title:
Indicator expiration:2026-08-15 12:00:00
[6a578ef4ac776ac521e7f84d] 2026-07-15 13:45:24.913000 | RDP honeypot logs for 2026/07/15
Author name:jnazario
Pulse modified:2026-07-15 13:45:24.913000
Indicator created:2026-07-15 13:45:25
Indicator role:bruteforce
Indicator title:
Indicator expiration:2026-08-14 00:00:00
[6a577b0cea4d68fc6138b25a] 2026-07-15 12:20:28.623000 | RDP honeypot logs for 2026/07/15
Author name:jnazario
Pulse modified:2026-07-15 12:20:28.623000
Indicator created:2026-07-15 12:20:29
Indicator role:None
Indicator title:
Indicator expiration:2026-08-14 12:00:00
[6a5a1e12b3917bf232b76dea] 2026-07-17 12:20:34.011000 | RDP honeypot logs for 2026/07/17
Author name:jnazario
Pulse modified:2026-07-17 12:20:34.011000
Indicator created:2026-07-17 12:20:34
Indicator role:None
Indicator title:
Indicator expiration:2026-08-16 12:00:00
[6a7c65185710baa0646fa57d] 2026-08-12 12:20:40.166000 | RDP honeypot logs for 2026/08/12
Author name:jnazario
Pulse modified:2026-08-12 12:20:40.166000
Indicator created:2026-08-12 12:20:40
Indicator role:None
Indicator title:
Indicator expiration:2026-09-11 12:00:00
[6a7b13a0e6e6765701dd1a53] 2026-08-11 12:20:48.369000 | RDP honeypot logs for 2026/08/11
Author name:jnazario
Pulse modified:2026-08-11 12:20:48.369000
Indicator created:2026-08-11 12:20:49
Indicator role:None
Indicator title:
Indicator expiration:2026-09-10 12:00:00
[6a79c204b4196038c6f9da6e] 2026-08-10 12:20:20.646000 | RDP honeypot logs for 2026/08/10
Author name:jnazario
Pulse modified:2026-08-10 12:20:20.646000
Indicator created:2026-08-10 12:20:21
Indicator role:None
Indicator title:
Indicator expiration:2026-09-09 12:00:00
[6a7872ee63d84a35ed106976] 2026-08-09 12:30:37.699000 | RDP honeypot logs for 2026/08/09
Author name:jnazario
Pulse modified:2026-08-09 12:30:37.699000
Indicator created:2026-08-09 12:30:38
Indicator role:None
Indicator title:
Indicator expiration:2026-09-08 12:00:00
[6a732a8df6eafdfd07b7d6a2] 2026-08-05 12:20:29.867000 | RDP honeypot logs for 2026/08/05
Author name:jnazario
Pulse modified:2026-08-05 12:20:29.867000
Indicator created:2026-08-05 12:20:30
Indicator role:None
Indicator title:
Indicator expiration:2026-09-04 12:00:00
[6a6de552646a50b777bd3782] 2026-08-01 12:23:46.277000 | RDP honeypot logs for 2026/08/01
Author name:jnazario
Pulse modified:2026-08-01 12:23:46.277000
Indicator created:2026-08-01 12:23:47
Indicator role:None
Indicator title:
Indicator expiration:2026-08-31 12:00:00
[6a6c9310ed4d5b7ae6099dc5] 2026-07-31 12:20:32.559000 | RDP honeypot logs for 2026/07/31
Author name:jnazario
Pulse modified:2026-07-31 12:20:32.559000
Indicator created:2026-07-31 12:20:33
Indicator role:None
Indicator title:
Indicator expiration:2026-08-30 12:00:00
Origin AS
AS204428 - SS-Net
BGP Prefix
80.94.95.0/24
geo
Romania
🕑 Europe/Bucharest
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
80.94.92.0 - 80.94.95.255
last_activity
2026-08-29 18:13:58.053000
last_warden_event
2026-08-12 15:26:36
rep
0.1591035847462855
reserved_range
0
ts_added
2026-04-17 16:00:32.478000
ts_last_update
2026-09-20 16:00:41.783000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses