IP address


.00798.80.4.12scanner-98-80-4-12.reposify.net
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
Echelon TLS/SSL crawler
98.80.4.12 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-07-12 09:40:00.417000
Was present on blacklist at: 2026-05-04 09:40, 2026-05-05 09:40, 2026-05-07 09:40, 2026-05-08 09:40, 2026-05-09 09:40, 2026-05-10 09:40, 2026-05-11 09:40, 2026-05-12 09:40, 2026-05-13 09:40, 2026-07-06 09:40, 2026-07-07 09:40, 2026-07-08 09:40, 2026-07-09 09:40, 2026-07-10 09:40, 2026-07-11 09:40, 2026-07-12 09:40
Spamhaus XBL CBL
98.80.4.12 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-07-21 19:05:20.404000
Was present on blacklist at: 2026-05-12 19:05, 2026-05-19 19:05
Echelon web crawler
98.80.4.12 is listed on the Echelon web crawler blacklist.

Description: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-05-22 09:50:00.429000
Was present on blacklist at: 2026-05-18 09:50, 2026-05-19 09:50, 2026-05-20 09:50, 2026-05-21 09:50, 2026-05-22 09:50
Spamhaus SBL CSS
98.80.4.12 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-07-21 19:05:20.404000
Was present on blacklist at: 2026-05-26 19:05, 2026-06-02 19:05, 2026-07-21 19:05

Threat categories

TLRoleCategoryDetails
42 src login protocol: ftp
port: 21
25 src scan

Warden events (15)
2026-07-23
IntrusionUserCompromise (node.cfb4f7): 3
2026-07-11
IntrusionUserCompromise (node.cfb4f7): 1
2026-07-10
IntrusionUserCompromise (node.cfb4f7): 1
2026-07-08
IntrusionUserCompromise (node.cfb4f7): 1
2026-07-05
IntrusionUserCompromise (node.cfb4f7): 1
2026-07-03
IntrusionUserCompromise (node.cfb4f7): 1
2026-06-23
IntrusionUserCompromise (node.cfb4f7): 2
2026-06-07
IntrusionUserCompromise (node.cfb4f7): 1
2026-05-27
IntrusionUserCompromise (node.cfb4f7): 1
2026-05-19
IntrusionUserCompromise (node.cfb4f7): 1
2026-05-13
IntrusionUserCompromise (node.cfb4f7): 1
2026-04-27
IntrusionUserCompromise (node.cfb4f7): 1
Origin AS
AS14618 - AMAZON-AES
BGP Prefix
98.80.0.0/13
geo
United States, Ashburn
🕑 America/New_York
hostname
scanner-98-80-4-12.reposify.net
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
98.80.0.0 - 98.95.255.255
last_activity
2026-07-23 07:09:58
last_warden_event
2026-07-23 07:09:58
rep
0.006995087448453674
reserved_range
0
Shodan's InternetDB
Open ports: 80
Tags: cloud
CPEs:
ts_added
2026-04-28 19:05:10.838000
ts_last_update
2026-07-24 19:05:20.129000

Warden event timeline

DShield event timeline

Presence on blacklists