IP address


.85194.26.106.80
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
Spamhaus SBL
94.26.106.80 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-29 16:50:40.314000
Was present on blacklist at: 2026-06-15 16:50, 2026-06-22 16:50, 2026-06-29 16:50
Spamhaus DROP
94.26.106.80 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-29 16:50:40.314000
Was present on blacklist at: 2026-06-15 16:50, 2026-06-22 16:50, 2026-06-29 16:50
AbuseIPDB
94.26.106.80 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-06-29 04:00:00.598000
Was present on blacklist at: 2026-06-17 04:00, 2026-06-18 04:00, 2026-06-19 04:00, 2026-06-21 04:00, 2026-06-22 04:00, 2026-06-25 04:00, 2026-06-26 04:00, 2026-06-27 04:00, 2026-06-28 04:00, 2026-06-29 04:00
Spamhaus XBL CBL
94.26.106.80 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-29 16:50:40.314000
Was present on blacklist at: 2026-06-22 16:50

Threat categories

TLRoleCategoryDetails
69 src scan port: 1, 3000, 3001, 7001, 8080, 61616
25 src

Warden events (3662)
2026-06-30
ReconScanning (node.4dc198): 36
ReconScanning (node.9c1411): 8
ReconScanning (node.368407): 3
ReconScanning (node.ce2b59): 3
2026-06-29
ReconScanning (node.4dc198): 234
ReconScanning (node.9c1411): 67
ReconScanning (node.368407): 45
ReconScanning (node.ce2b59): 31
2026-06-28
ReconScanning (node.4dc198): 267
ReconScanning (node.9c1411): 67
ReconScanning (node.368407): 27
ReconScanning (node.ce2b59): 31
2026-06-27
ReconScanning (node.9c1411): 67
ReconScanning (node.368407): 39
ReconScanning (node.4dc198): 195
ReconScanning (node.ce2b59): 31
2026-06-26
ReconScanning (node.4dc198): 244
ReconScanning (node.9c1411): 79
ReconScanning (node.368407): 42
ReconScanning (node.ce2b59): 30
2026-06-25
ReconScanning (node.4dc198): 144
ReconScanning (node.368407): 23
ReconScanning (node.9c1411): 56
ReconScanning (node.ce2b59): 23
2026-06-24
ReconScanning (node.4dc198): 90
ReconScanning (node.9c1411): 46
ReconScanning (node.ce2b59): 19
ReconScanning (node.368407): 43
2026-06-23
ReconScanning (node.ce2b59): 5
ReconScanning (node.9c1411): 6
ReconScanning (node.4dc198): 19
ReconScanning (node.368407): 3
2026-06-22
ReconScanning (node.4dc198): 199
ReconScanning (node.9c1411): 53
ReconScanning (node.ce2b59): 22
ReconScanning (node.368407): 26
2026-06-21
ReconScanning (node.ce2b59): 31
ReconScanning (node.4dc198): 180
ReconScanning (node.9c1411): 72
ReconScanning (node.368407): 49
2026-06-20
ReconScanning (node.4dc198): 169
ReconScanning (node.9c1411): 64
ReconScanning (node.ce2b59): 26
ReconScanning (node.368407): 48
2026-06-19
ReconScanning (node.368407): 59
ReconScanning (node.4dc198): 188
ReconScanning (node.9c1411): 72
ReconScanning (node.ce2b59): 31
2026-06-18
ReconScanning (node.368407): 91
ReconScanning (node.4dc198): 109
ReconScanning (node.9c1411): 52
ReconScanning (node.ce2b59): 22
2026-06-17
ReconScanning (node.368407): 16
ReconScanning (node.4dc198): 16
ReconScanning (node.9c1411): 2
2026-06-16
ReconScanning (node.9c1411): 1
2026-06-15
ReconScanning (node.4dc198): 18
ReconScanning (node.368407): 18
ReconScanning (node.9c1411): 5
DShield reports (IP summary, reports)
2026-06-17
Number of reports: 312
Distinct targets: 140
2026-06-18
Number of reports: 667
Distinct targets: 273
2026-06-19
Number of reports: 416
Distinct targets: 254
2026-06-20
Number of reports: 390
Distinct targets: 266
2026-06-21
Number of reports: 341
Distinct targets: 255
2026-06-22
Number of reports: 338
Distinct targets: 220
2026-06-23
Number of reports: 26
Distinct targets: 21
2026-06-24
Number of reports: 303
Distinct targets: 194
2026-06-25
Number of reports: 303
Distinct targets: 194
2026-06-26
Number of reports: 455
Distinct targets: 247
2026-06-27
Number of reports: 392
Distinct targets: 234
2026-06-28
Number of reports: 384
Distinct targets: 219
Origin AS
AS215607 - DF-Transit
AS197170 - TECHTIES-AS
BGP Prefix
94.26.106.0/24
geo
Germany, Kriftel
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
94.26.104.0 - 94.26.107.255
last_activity
2026-06-30 02:53:54
last_warden_event
2026-06-30 02:53:54
rep
0.8514259194731001
reserved_range
0
ts_added
2026-06-15 16:50:38.357000
ts_last_update
2026-06-30 02:54:41.123000

Warden event timeline

DShield event timeline

Presence on blacklists