IP address


.00287.120.125.213
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
87.120.125.213 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2024-12-05 03:50:01.027000
Was present on blacklist at: 2024-11-11 03:50, 2024-11-12 03:50, 2024-11-13 03:50, 2024-11-14 03:50, 2024-11-15 03:50, 2024-11-16 03:50, 2024-11-17 03:50, 2024-11-18 03:50, 2024-11-19 03:50, 2024-11-20 03:50, 2024-11-21 03:50, 2024-11-22 03:50, 2024-11-23 03:50, 2024-11-24 03:50, 2024-11-25 03:50, 2024-11-26 03:50, 2024-11-27 03:50, 2024-11-28 03:50, 2024-11-29 03:50, 2024-11-30 03:50, 2024-12-01 03:50, 2024-12-02 03:50, 2024-12-03 03:50, 2024-12-04 03:50, 2024-12-05 03:50
AbuseIPDB
87.120.125.213 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2024-12-10 05:00:00.352000
Was present on blacklist at: 2024-11-11 05:00, 2024-11-12 05:00, 2024-11-13 05:00, 2024-11-14 05:00, 2024-11-15 05:00, 2024-11-16 05:00, 2024-11-17 05:00, 2024-11-18 05:00, 2024-11-19 05:00, 2024-11-20 05:00, 2024-11-21 05:00, 2024-11-22 05:00, 2024-11-23 05:00, 2024-11-24 05:00, 2024-11-25 05:00, 2024-11-26 05:00, 2024-11-27 05:00, 2024-11-28 05:00, 2024-11-29 05:00, 2024-11-30 05:00, 2024-12-01 05:00, 2024-12-02 05:00, 2024-12-05 05:00, 2024-12-06 05:00, 2024-12-07 05:00, 2024-12-08 05:00, 2024-12-09 05:00, 2024-12-10 05:00
Turris greylist
87.120.125.213 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2024-12-11 22:15:00.323000
Was present on blacklist at: 2024-11-13 22:15, 2024-11-14 22:15, 2024-11-15 22:15, 2024-11-17 22:15, 2024-11-18 22:15, 2024-11-20 22:15, 2024-11-22 22:15, 2024-11-23 22:15, 2024-11-24 22:15, 2024-11-25 22:15, 2024-11-26 22:15, 2024-11-28 22:15, 2024-11-29 22:15, 2024-12-01 22:15, 2024-12-02 22:15, 2024-12-07 22:15, 2024-12-08 22:15, 2024-12-09 22:15, 2024-12-11 22:15
Spamhaus SBL
87.120.125.213 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-12-22 15:52:50.303000
Was present on blacklist at: 2024-11-24 15:52, 2024-12-01 15:52, 2024-12-08 15:52, 2024-12-15 15:52, 2024-12-22 15:52
Spamhaus DROP
87.120.125.213 is listed on the Spamhaus DROP blacklist.

Description: The Spamhaus DROP (Don't Route Or Peer) lists are advisory"drop all traffic" lists. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-12-22 15:52:50.303000
Was present on blacklist at: 2024-11-24 15:52, 2024-12-01 15:52, 2024-12-08 15:52, 2024-12-15 15:52, 2024-12-22 15:52
Blocklist.net.ua
87.120.125.213 is listed on the Blocklist.net.ua blacklist.

Description: BlockList contains IP addresses that perform attacks,<br>send spam or brute force passwords to the blocking list.
Type of feed: primary (feed detail page)

Last checked at: 2024-12-23 15:15:03.892000
Was present on blacklist at: 2024-12-08 19:15, 2024-12-08 23:15, 2024-12-09 03:15, 2024-12-09 07:15, 2024-12-09 11:15, 2024-12-09 15:15, 2024-12-09 19:15, 2024-12-09 23:15, 2024-12-10 03:15, 2024-12-10 07:15, 2024-12-10 11:15, 2024-12-10 15:15, 2024-12-10 19:15, 2024-12-10 23:15, 2024-12-11 03:15, 2024-12-11 07:15, 2024-12-11 11:15, 2024-12-11 15:15, 2024-12-11 19:15, 2024-12-11 23:15, 2024-12-12 03:15, 2024-12-12 07:15, 2024-12-12 11:15, 2024-12-12 15:15, 2024-12-12 19:15, 2024-12-12 23:15, 2024-12-13 03:15, 2024-12-13 07:15, 2024-12-13 11:15, 2024-12-13 15:15, 2024-12-13 19:15, 2024-12-13 23:15, 2024-12-14 03:15, 2024-12-14 07:15, 2024-12-14 11:15, 2024-12-14 15:15, 2024-12-14 19:15, 2024-12-14 23:15, 2024-12-15 03:15, 2024-12-15 07:15, 2024-12-15 11:15, 2024-12-15 15:15, 2024-12-15 19:15, 2024-12-15 23:15, 2024-12-16 03:15, 2024-12-16 07:15, 2024-12-16 11:15, 2024-12-16 15:15, 2024-12-16 19:15, 2024-12-16 23:15, 2024-12-17 03:15, 2024-12-17 07:15, 2024-12-17 11:15, 2024-12-17 15:15, 2024-12-17 19:15, 2024-12-17 23:15, 2024-12-18 03:15, 2024-12-18 07:15, 2024-12-18 11:15, 2024-12-18 15:15, 2024-12-18 19:15, 2024-12-18 23:15, 2024-12-19 03:15, 2024-12-19 07:15, 2024-12-19 11:15, 2024-12-19 15:15, 2024-12-19 19:15, 2024-12-19 23:15, 2024-12-20 03:15, 2024-12-20 07:15, 2024-12-20 11:15, 2024-12-20 15:15, 2024-12-20 19:15, 2024-12-20 23:15, 2024-12-21 03:15, 2024-12-21 07:15, 2024-12-21 11:15, 2024-12-21 15:15, 2024-12-21 19:15, 2024-12-21 23:15, 2024-12-22 03:15, 2024-12-22 07:15, 2024-12-22 11:15, 2024-12-22 15:15, 2024-12-22 19:15, 2024-12-22 23:15, 2024-12-23 03:15, 2024-12-23 07:15, 2024-12-23 11:15, 2024-12-23 15:15
Spamhaus PBL
87.120.125.213 is listed on the Spamhaus PBL blacklist.

Description: The Spamhaus PBL is a DNSBL database of end-user IP address ranges which should not be delivering unauthenticated SMTP email to any Internet mail server except those provided for specifically by an ISP for that customer's use.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2024-12-22 15:52:50.303000
Was present on blacklist at: 2024-12-15 15:52, 2024-12-22 15:52
Warden events (5631)
2024-12-12
ReconScanning (node.ce2b59): 1
2024-12-10
ReconScanning (node.ce2b59): 32
ReconScanning (node.4dc198): 69
ReconScanning (node.368407): 68
2024-12-09
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 30
ReconScanning (node.368407): 29
ReconScanning (node.5f02e7): 1
2024-12-08
ReconScanning (node.368407): 155
ReconScanning (node.4dc198): 155
ReconScanning (node.ce2b59): 32
ReconScanning (node.5f02e7): 3
2024-12-07
ReconScanning (node.368407): 51
ReconScanning (node.4dc198): 52
ReconScanning (node.ce2b59): 31
ReconScanning (node.5f02e7): 2
2024-12-06
ReconScanning (node.4dc198): 96
ReconScanning (node.368407): 99
ReconScanning (node.ce2b59): 30
2024-12-05
ReconScanning (node.ce2b59): 30
ReconScanning (node.368407): 105
ReconScanning (node.4dc198): 103
2024-12-04
ReconScanning (node.ce2b59): 16
2024-12-02
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 1
ReconScanning (node.ce2b59): 15
ReconScanning (node.5f02e7): 1
2024-12-01
ReconScanning (node.ce2b59): 30
ReconScanning (node.368407): 44
ReconScanning (node.4dc198): 44
2024-11-30
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 92
ReconScanning (node.368407): 91
2024-11-29
ReconScanning (node.ce2b59): 31
ReconScanning (node.5f02e7): 1
ReconScanning (node.4dc198): 43
ReconScanning (node.368407): 43
2024-11-28
ReconScanning (node.ce2b59): 30
ReconScanning (node.5f02e7): 1
ReconScanning (node.368407): 38
ReconScanning (node.4dc198): 38
2024-11-27
ReconScanning (node.ce2b59): 31
ReconScanning (node.368407): 76
ReconScanning (node.4dc198): 75
2024-11-26
ReconScanning (node.ce2b59): 32
ReconScanning (node.5f02e7): 1
ReconScanning (node.368407): 77
ReconScanning (node.4dc198): 77
2024-11-25
ReconScanning (node.ce2b59): 31
ReconScanning (node.5f02e7): 2
ReconScanning (node.368407): 110
ReconScanning (node.4dc198): 104
2024-11-24
ReconScanning (node.ce2b59): 31
ReconScanning (node.368407): 173
ReconScanning (node.4dc198): 170
ReconScanning (node.5f02e7): 2
2024-11-23
ReconScanning (node.ce2b59): 27
ReconScanning (node.4dc198): 133
ReconScanning (node.368407): 133
2024-11-22
ReconScanning (node.ce2b59): 29
ReconScanning (node.4dc198): 78
ReconScanning (node.368407): 78
2024-11-21
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 42
ReconScanning (node.368407): 41
2024-11-20
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 89
ReconScanning (node.368407): 91
2024-11-19
ReconScanning (node.4dc198): 139
ReconScanning (node.368407): 136
ReconScanning (node.ce2b59): 32
2024-11-18
ReconScanning (node.ce2b59): 32
ReconScanning (node.368407): 85
ReconScanning (node.4dc198): 82
ReconScanning (node.5f02e7): 1
2024-11-17
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 41
ReconScanning (node.368407): 40
ReconScanning (node.5f02e7): 1
2024-11-16
ReconScanning (node.4dc198): 83
ReconScanning (node.368407): 83
ReconScanning (node.ce2b59): 31
2024-11-15
ReconScanning (node.ce2b59): 30
ReconScanning (node.368407): 65
ReconScanning (node.4dc198): 61
2024-11-14
ReconScanning (node.4dc198): 34
ReconScanning (node.368407): 35
ReconScanning (node.5f02e7): 1
ReconScanning (node.ce2b59): 5
2024-11-13
ReconScanning (node.5f02e7): 2
ReconScanning (node.ce2b59): 25
ReconScanning (node.368407): 122
ReconScanning (node.4dc198): 114
2024-11-12
ReconScanning (node.ce2b59): 32
ReconScanning (node.4dc198): 75
ReconScanning (node.368407): 81
ReconScanning (node.5f02e7): 1
2024-11-11
ReconScanning (node.4dc198): 179
ReconScanning (node.368407): 188
ReconScanning (node.ce2b59): 32
ReconScanning (node.5f02e7): 2
2024-11-10
ReconScanning (node.ce2b59): 24
ReconScanning (node.368407): 59
ReconScanning (node.4dc198): 56
DShield reports (IP summary, reports)
2024-11-10
Number of reports: 1504
Distinct targets: 1122
2024-11-11
Number of reports: 4357
Distinct targets: 3036
2024-11-12
Number of reports: 4321
Distinct targets: 3091
2024-11-13
Number of reports: 3976
Distinct targets: 2505
2024-11-14
Number of reports: 4158
Distinct targets: 2712
2024-11-15
Number of reports: 4036
Distinct targets: 2279
2024-11-16
Number of reports: 4153
Distinct targets: 2325
2024-11-17
Number of reports: 3852
Distinct targets: 2081
2024-11-18
Number of reports: 3186
Distinct targets: 1937
2024-11-19
Number of reports: 3630
Distinct targets: 2372
2024-11-20
Number of reports: 3440
Distinct targets: 2057
2024-11-21
Number of reports: 3829
Distinct targets: 2098
2024-11-22
Number of reports: 3713
Distinct targets: 2381
2024-11-23
Number of reports: 2795
Distinct targets: 2231
2024-11-24
Number of reports: 4444
Distinct targets: 2834
2024-11-25
Number of reports: 4438
Distinct targets: 2866
2024-11-26
Number of reports: 4433
Distinct targets: 2911
2024-11-27
Number of reports: 4315
Distinct targets: 2470
2024-11-28
Number of reports: 4027
Distinct targets: 2640
2024-11-29
Number of reports: 3732
Distinct targets: 2005
2024-11-30
Number of reports: 3456
Distinct targets: 2244
2024-12-01
Number of reports: 3674
Distinct targets: 2398
2024-12-02
Number of reports: 1842
Distinct targets: 1150
2024-12-04
Number of reports: 2504
Distinct targets: 1499
2024-12-05
Number of reports: 4602
Distinct targets: 2917
2024-12-06
Number of reports: 4154
Distinct targets: 2728
2024-12-07
Number of reports: 4702
Distinct targets: 2697
2024-12-08
Number of reports: 4852
Distinct targets: 2959
2024-12-09
Number of reports: 5049
Distinct targets: 3077
2024-12-10
Number of reports: 4012
Distinct targets: 2281
Origin AS
AS401115 - EKABI
BGP Prefix
87.120.125.0/24
geo
Bulgaria
🕑 Europe/Sofia
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
87.120.112.0 - 87.120.127.255
last_activity
2024-12-12 23:23:09
last_warden_event
2024-12-12 23:23:09
rep
0.0023809523809523807
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80
Tags: scanner, eol-product
CPEs: cpe:/a:openbsd:openssh:9.2p1, cpe:/a:f5:nginx:1.22.1, cpe:/o:linux:linux_kernel, cpe:/o:debian:debian_linux
ts_added
2024-11-10 15:52:47.112000
ts_last_update
2024-12-25 15:52:50.300000

Warden event timeline

DShield event timeline

Presence on blacklists