IP address


--81.161.238.22
Shodan(more info)
Passive DNS
Tags:
IP blacklists
blocklist.de SSH
81.161.238.22 is listed on the blocklist.de SSH blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2024-12-13 17:05:00.326000
Was present on blacklist at: 2024-12-06 23:05, 2024-12-07 05:05, 2024-12-07 11:05, 2024-12-07 17:05, 2024-12-07 23:05, 2024-12-08 05:05, 2024-12-08 11:05, 2024-12-08 17:05, 2024-12-08 23:05, 2024-12-09 05:05, 2024-12-09 11:05, 2024-12-09 17:05, 2024-12-09 23:05, 2024-12-11 11:05, 2024-12-11 17:05, 2024-12-11 23:05, 2024-12-12 05:05, 2024-12-12 11:05, 2024-12-12 17:05, 2024-12-12 23:05, 2024-12-13 05:05, 2024-12-13 11:05, 2024-12-13 17:05
Spamhaus SBL
81.161.238.22 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-01-10 23:08:42.037000
Was present on blacklist at: 2024-12-06 23:08, 2024-12-13 23:08, 2024-12-20 23:08, 2024-12-27 23:08, 2025-01-03 23:08, 2025-01-10 23:08
Spamhaus DROP
81.161.238.22 is listed on the Spamhaus DROP blacklist.

Description: The Spamhaus DROP (Don't Route Or Peer) lists are advisory"drop all traffic" lists. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-01-10 23:08:42.037000
Was present on blacklist at: 2024-12-06 23:08, 2024-12-13 23:08, 2024-12-20 23:08, 2024-12-27 23:08, 2025-01-03 23:08, 2025-01-10 23:08
BruteForceBlocker
81.161.238.22 is listed on the BruteForceBlocker blacklist.

Description: Daniel Gerzo's BruteForceBlocker. The list is made by perl script,<br>that works along with pf - OpenBSD's firewall and it's main<br>purpose is to block SSH bruteforce attacks via firewall.
Type of feed: primary (feed detail page)

Last checked at: 2025-01-05 03:52:00.210000
Was present on blacklist at: 2024-12-07 03:52, 2024-12-08 03:52, 2024-12-09 03:52, 2024-12-10 03:52, 2024-12-11 03:52, 2024-12-12 03:52, 2024-12-13 03:52, 2024-12-14 03:52, 2024-12-15 03:52, 2024-12-16 03:52, 2024-12-17 03:52, 2024-12-18 03:52, 2024-12-19 03:52, 2024-12-20 03:52, 2024-12-21 03:52, 2024-12-22 03:52, 2024-12-23 03:52, 2024-12-24 03:52, 2024-12-25 03:52, 2024-12-26 03:52, 2024-12-27 03:52, 2024-12-28 03:52, 2024-12-29 03:52, 2024-12-30 03:52, 2024-12-31 03:52, 2025-01-01 03:52, 2025-01-02 03:52, 2025-01-03 03:52, 2025-01-04 03:52, 2025-01-05 03:52
FireHOL anonymizers
81.161.238.22 is listed on the FireHOL anonymizers blacklist.

Description: List of anonymizing IPs, aggregated from multiple lists by FireHOL.
Type of feed: secondary (feed detail page)

Last checked at: 2025-01-15 18:10:32
Was present on blacklist at: 2025-01-01 18:09, 2025-01-02 18:10, 2025-01-03 18:10, 2025-01-04 18:09, 2025-01-05 18:09, 2025-01-06 18:09, 2025-01-07 18:10, 2025-01-09 00:11, 2025-01-09 18:12, 2025-01-10 18:11, 2025-01-11 18:08, 2025-01-12 18:13, 2025-01-13 18:08, 2025-01-14 18:08, 2025-01-15 18:10
DShield reports (IP summary, reports)
2024-12-17
Number of reports: 3645
Distinct targets: 547
2024-12-18
Number of reports: 2601
Distinct targets: 2013
2024-12-19
Number of reports: 2425
Distinct targets: 1750
2024-12-20
Number of reports: 2907
Distinct targets: 2013
2024-12-21
Number of reports: 1851
Distinct targets: 1851
2024-12-22
Number of reports: 3409
Distinct targets: 2365
2024-12-23
Number of reports: 3476
Distinct targets: 2341
2024-12-24
Number of reports: 2418
Distinct targets: 2418
2024-12-25
Number of reports: 2479
Distinct targets: 1791
2024-12-26
Number of reports: 3373
Distinct targets: 2314
2024-12-27
Number of reports: 2788
Distinct targets: 1875
2024-12-28
Number of reports: 2497
Distinct targets: 1785
2024-12-29
Number of reports: 2620
Distinct targets: 1895
2024-12-30
Number of reports: 2527
Distinct targets: 2527
2024-12-31
Number of reports: 1394
Distinct targets: 995
2025-01-01
Number of reports: 1936
Distinct targets: 1936
2025-01-02
Number of reports: 2422
Distinct targets: 1773
2025-01-03
Number of reports: 2909
Distinct targets: 2103
2025-01-04
Number of reports: 4119
Distinct targets: 2984
2025-01-05
Number of reports: 1520
Distinct targets: 1520
2025-01-06
Number of reports: 2968
Distinct targets: 2060
2025-01-07
Number of reports: 1650
Distinct targets: 1650
2025-01-08
Number of reports: 3522
Distinct targets: 2581
2025-01-09
Number of reports: 2692
Distinct targets: 1938
2025-01-10
Number of reports: 2897
Distinct targets: 2082
2025-01-11
Number of reports: 2422
Distinct targets: 1754
2025-01-12
Number of reports: 1802
Distinct targets: 1300
2025-01-13
Number of reports: 1284
Distinct targets: 907
2025-01-14
Number of reports: 2642
Distinct targets: 1843
2025-01-15
Number of reports: 2576
Distinct targets: 1788
Origin AS
AS401116 - NYBULA
BGP Prefix
81.161.238.0/24
geo
Netherlands, Amsterdam
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
81.161.236.0 - 81.161.239.255
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags:
CPEs: cpe:/a:openbsd:openssh:8.2p1, cpe:/o:canonical:ubuntu_linux
ts_added
2024-12-06 23:08:35.459000
ts_last_update
2025-01-16 05:02:06.736000

Warden event timeline

DShield event timeline

Presence on blacklists