IP address


.29491.92.47.220
Shodan(more info)
Passive DNS
Tags:
IP blacklists
CI Army
91.92.47.220 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-08-16 02:50:00.833000
Was present on blacklist at: 2026-08-11 02:50, 2026-08-12 02:50, 2026-08-14 02:50, 2026-08-15 02:50, 2026-08-16 02:50
DShield Block
91.92.47.220 was recently listed on the DShield Block blacklist, but currently it is not.

Description: Recommended Block List by DShield.org. It summarizes the top 20 attacking<br>class C (/24) subnets over the last three days.
Type of feed: secondary (feed detail page)

Last checked at: 2026-09-07 04:50:00
Was present on blacklist at: 2026-09-01 04:50, 2026-09-02 04:50
Spamhaus SBL
91.92.47.220 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-06 20:00:19.625000
Was present on blacklist at: 2026-09-06 20:00
Spamhaus DROP
91.92.47.220 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-09-06 20:00:19.625000
Was present on blacklist at: 2026-09-06 20:00

Threat categories

TLRoleCategoryDetails
38 src scan

Warden events (827)
2026-08-30
ReconScanning (node.368407): 1
2026-08-16
ReconScanning (node.368407): 1
ReconScanning (node.9c1411): 4
2026-08-15
ReconScanning (node.9c1411): 10
2026-08-14
ReconScanning (node.4dc198): 24
ReconScanning (node.368407): 23
ReconScanning (node.ce2b59): 9
ReconScanning (node.9c1411): 35
2026-08-13
ReconScanning (node.ce2b59): 20
ReconScanning (node.368407): 71
ReconScanning (node.4dc198): 71
2026-08-12
ReconScanning (node.9c1411): 30
ReconScanning (node.ce2b59): 1
2026-08-11
ReconScanning (node.4dc198): 114
ReconScanning (node.9c1411): 33
ReconScanning (node.368407): 110
ReconScanning (node.ce2b59): 35
2026-08-10
ReconScanning (node.4dc198): 78
ReconScanning (node.ce2b59): 23
ReconScanning (node.368407): 79
ReconScanning (node.9c1411): 24
2026-08-09
ReconScanning (node.ce2b59): 10
ReconScanning (node.4dc198): 11
ReconScanning (node.368407): 10
DShield reports (IP summary, reports)
2026-08-09
Number of reports: 46
Distinct targets: 33
2026-08-10
Number of reports: 46
Distinct targets: 33
2026-08-11
Number of reports: 263
Distinct targets: 191
2026-08-14
Number of reports: 88
Distinct targets: 61
2026-08-15
Number of reports: 88
Distinct targets: 61
2026-08-31
Number of reports: 31
Distinct targets: 22
Origin AS
AS197170 - TECHTIES-AS
BGP Prefix
91.92.47.0/24
geo
Netherlands, Amsterdam
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
91.92.40.0 - 91.92.47.255
last_activity
2026-08-30 19:54:19
last_warden_event
2026-08-30 19:54:19
rep
0.2937213357831824
reserved_range
0
ts_added
2026-08-09 11:29:41.239000
ts_last_update
2026-09-07 11:29:52.065000

Warden event timeline

DShield event timeline

Presence on blacklists