IP address


.16089.248.173.215
Shodan(more info)
Passive DNS
Tags:
IP blacklists
CI Army
89.248.173.215 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-09-11 02:50:00.884000
Was present on blacklist at: 2026-06-14 02:50, 2026-06-15 02:50, 2026-06-17 02:50, 2026-06-18 02:50, 2026-06-19 02:50, 2026-06-20 02:50, 2026-06-21 02:50, 2026-06-22 02:50, 2026-06-23 02:50, 2026-06-24 02:50, 2026-06-25 02:50, 2026-06-26 02:50, 2026-06-27 02:50, 2026-06-28 02:50, 2026-06-29 02:50, 2026-06-30 02:50, 2026-07-01 02:50, 2026-07-02 02:50, 2026-07-03 02:50, 2026-07-04 02:50, 2026-07-05 02:50, 2026-07-06 02:50, 2026-07-07 02:50, 2026-07-08 02:50, 2026-07-09 02:50, 2026-07-10 02:50, 2026-07-11 02:50, 2026-07-12 02:50, 2026-07-13 02:50, 2026-07-14 02:50, 2026-07-15 02:50, 2026-07-17 02:50, 2026-07-18 02:50, 2026-07-19 02:50, 2026-07-20 02:50, 2026-07-21 02:50, 2026-07-22 02:50, 2026-07-23 02:50, 2026-07-24 02:50, 2026-07-25 02:50, 2026-07-27 02:50, 2026-07-28 02:50, 2026-07-29 02:50, 2026-07-30 02:50, 2026-07-31 02:50, 2026-08-01 02:50, 2026-08-02 02:50, 2026-08-03 02:50, 2026-08-04 02:50, 2026-08-05 02:50, 2026-08-06 02:50, 2026-08-07 02:50, 2026-08-08 02:50, 2026-08-09 02:50, 2026-08-10 02:50, 2026-08-11 02:50, 2026-08-12 02:50, 2026-08-13 02:50, 2026-08-14 02:50, 2026-08-15 02:50, 2026-08-16 02:50, 2026-08-17 02:50, 2026-08-18 02:50, 2026-08-19 02:50, 2026-08-20 02:50, 2026-08-21 02:50, 2026-08-22 02:50, 2026-08-23 02:50, 2026-08-24 02:50, 2026-08-25 02:50, 2026-08-26 02:50, 2026-08-27 02:50, 2026-08-28 02:50, 2026-08-29 02:50, 2026-08-30 02:50, 2026-08-31 02:50, 2026-09-01 02:50, 2026-09-02 02:50, 2026-09-03 02:50, 2026-09-04 02:50, 2026-09-05 02:50, 2026-09-06 02:50, 2026-09-08 02:50, 2026-09-09 02:50, 2026-09-10 02:50, 2026-09-11 02:50
Echelon web crawler
89.248.173.215 is listed on the Echelon web crawler blacklist.

Description: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-08-31 09:50:00.388000
Was present on blacklist at: 2026-06-15 09:50, 2026-06-16 09:50, 2026-06-17 09:50, 2026-06-18 09:50, 2026-06-19 09:50, 2026-06-20 09:50, 2026-06-21 09:50, 2026-06-22 09:50, 2026-07-22 09:50, 2026-07-23 09:50, 2026-07-24 09:50, 2026-07-25 09:50, 2026-07-26 09:50, 2026-07-27 09:50, 2026-07-28 09:50, 2026-07-29 09:50, 2026-07-30 09:50, 2026-07-31 09:50, 2026-08-01 09:50, 2026-08-02 09:50, 2026-08-03 09:50, 2026-08-04 09:50, 2026-08-05 09:50, 2026-08-24 09:50, 2026-08-25 09:50, 2026-08-26 09:50, 2026-08-27 09:50, 2026-08-28 09:50, 2026-08-29 09:50, 2026-08-30 09:50, 2026-08-31 09:50
Echelon TLS/SSL crawler
89.248.173.215 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-08-31 09:40:00.402000
Was present on blacklist at: 2026-06-14 09:40, 2026-06-15 09:40, 2026-06-17 09:40, 2026-06-18 09:40, 2026-06-19 09:40, 2026-06-20 09:40, 2026-06-21 09:40, 2026-06-22 09:40, 2026-06-23 09:40, 2026-06-24 09:40, 2026-07-29 09:40, 2026-07-30 09:40, 2026-07-31 09:40, 2026-08-01 09:40, 2026-08-02 09:40, 2026-08-03 09:40, 2026-08-04 09:40, 2026-08-05 09:40, 2026-08-24 09:40, 2026-08-25 09:40, 2026-08-26 09:40, 2026-08-27 09:40, 2026-08-28 09:40, 2026-08-29 09:40, 2026-08-30 09:40, 2026-08-31 09:40
AbuseIPDB
89.248.173.215 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-02 04:00:00.668000
Was present on blacklist at: 2026-06-15 04:00, 2026-06-17 04:00, 2026-06-22 04:00, 2026-06-24 04:00, 2026-06-26 04:00, 2026-06-29 04:00, 2026-07-03 04:00, 2026-07-08 04:00, 2026-07-10 04:00, 2026-07-13 04:00, 2026-07-15 04:00, 2026-07-17 04:00, 2026-07-20 04:00, 2026-07-24 04:00, 2026-07-27 04:00, 2026-07-29 04:00, 2026-07-31 04:00, 2026-08-05 04:00, 2026-08-07 04:00, 2026-08-10 04:00, 2026-08-12 04:00, 2026-08-14 04:00, 2026-08-17 04:00, 2026-08-19 04:00, 2026-08-26 04:00, 2026-09-02 04:00

Threat categories

TLRoleCategoryDetails
47 src scan
26 src

DShield reports (IP summary, reports)
2026-06-13
Number of reports: 110
Distinct targets: 68
2026-06-17
Number of reports: 181
Distinct targets: 90
2026-06-19
Number of reports: 96
Distinct targets: 57
2026-06-22
Number of reports: 116
Distinct targets: 69
2026-06-24
Number of reports: 120
Distinct targets: 70
2026-06-25
Number of reports: 120
Distinct targets: 70
2026-06-26
Number of reports: 106
Distinct targets: 59
2026-06-29
Number of reports: 101
Distinct targets: 62
2026-06-30
Number of reports: 101
Distinct targets: 62
2026-07-01
Number of reports: 102
Distinct targets: 62
2026-07-03
Number of reports: 100
Distinct targets: 60
2026-07-06
Number of reports: 87
Distinct targets: 59
2026-07-07
Number of reports: 87
Distinct targets: 59
2026-07-08
Number of reports: 123
Distinct targets: 74
2026-07-13
Number of reports: 98
Distinct targets: 59
2026-07-17
Number of reports: 116
Distinct targets: 70
2026-07-18
Number of reports: 116
Distinct targets: 70
2026-07-20
Number of reports: 129
Distinct targets: 77
2026-07-24
Number of reports: 124
Distinct targets: 80
2026-07-31
Number of reports: 143
Distinct targets: 84
2026-08-01
Number of reports: 143
Distinct targets: 84
2026-08-03
Number of reports: 77
Distinct targets: 46
2026-08-05
Number of reports: 134
Distinct targets: 79
2026-08-11
Number of reports: 95
Distinct targets: 53
2026-08-12
Number of reports: 92
Distinct targets: 52
2026-08-14
Number of reports: 89
Distinct targets: 55
2026-08-15
Number of reports: 89
Distinct targets: 55
2026-08-17
Number of reports: 87
Distinct targets: 59
2026-08-24
Number of reports: 110
Distinct targets: 72
2026-08-25
Number of reports: 110
Distinct targets: 72
2026-08-28
Number of reports: 101
Distinct targets: 64
2026-09-04
Number of reports: 105
Distinct targets: 68
2026-09-08
Number of reports: 95
Distinct targets: 59
Origin AS
AS202425 - INT-NETWORK
BGP Prefix
89.248.173.0/24
geo
Netherlands, Amsterdam
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
89.248.160.0 - 89.248.175.255
rep
0.15995890155172388
reserved_range
0
ts_added
2026-05-16 05:00:33.430000
ts_last_update
2026-09-11 05:01:38.158000

Warden event timeline

DShield event timeline

Presence on blacklists