IP address


--104.245.241.157
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
104.245.241.157 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-04-25 20:38:30.033000
Was present on blacklist at: 2025-04-04 20:38, 2025-04-11 20:38, 2025-04-18 20:38, 2025-04-25 20:38
Spamhaus DROP
104.245.241.157 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-04-25 20:38:30.033000
Was present on blacklist at: 2025-04-04 20:38, 2025-04-11 20:38, 2025-04-18 20:38, 2025-04-25 20:38
OTX pulses
[67efc6ed5285702a3440969a] 2025-04-04 11:47:57.825000 | Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign
Author name:AlienVault
Pulse modified:2025-04-04 17:19:20.566000
Indicator created:2025-04-04 11:47:58
Indicator role:None
Indicator title:
Indicator expiration:2025-05-04 11:00:00
Origin AS
AS214943 - RAILNET
BGP Prefix
104.245.241.0/24
geo
United States
🕑 America/Chicago
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
104.245.240.0 - 104.245.243.255
last_activity
2025-04-04 20:38:25.984000
reserved_range
0
Shodan's InternetDB
Open ports: 25, 80, 8181
Tags: self-signed
CPEs:
ts_added
2025-04-04 20:38:25.990000
ts_last_update
2025-04-29 20:38:30.414000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses