IP address


--104.28.239.218
Shodan(more info)
Passive DNS
Tags:
IP blacklists
DataPlane VNC RFB
104.28.239.218 is listed on the DataPlane VNC RFB blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs initiating<br>an unsolicited VNC remote frame buffer (RFB) session to a remote host.
Type of feed: primary (feed detail page)

Last checked at: 2025-11-05 03:10:01.443000
Was present on blacklist at: 2025-10-29 15:10, 2025-10-29 19:10, 2025-10-30 03:10, 2025-10-30 07:10, 2025-10-30 15:10, 2025-10-30 19:10, 2025-10-31 03:10, 2025-10-31 07:10, 2025-10-31 15:10, 2025-10-31 19:10, 2025-11-01 07:10, 2025-11-01 15:10, 2025-11-01 19:10, 2025-11-02 03:10, 2025-11-02 07:10, 2025-11-02 15:10, 2025-11-02 19:10, 2025-11-03 03:10, 2025-11-03 07:10, 2025-11-03 15:10, 2025-11-03 19:10, 2025-11-04 03:10, 2025-11-04 07:10, 2025-11-04 15:10, 2025-11-04 19:10, 2025-11-05 03:10
Spamhaus SBL CSS
104.28.239.218 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-09 05:10:34.554000
Was present on blacklist at: 2025-12-02 05:10, 2025-12-09 05:10
Spamhaus XBL CBL
104.28.239.218 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-09 05:10:34.554000
Was present on blacklist at: 2025-12-02 05:10, 2025-12-09 05:10
DShield reports (IP summary, reports)
2025-10-27
Number of reports: 48
Distinct targets: 6
2025-10-29
Number of reports: 41
Distinct targets: 6
2025-10-30
Number of reports: 24
Distinct targets: 3
2025-11-01
Number of reports: 105
Distinct targets: 10
2025-11-02
Number of reports: 105
Distinct targets: 10
2025-11-07
Number of reports: 35
Distinct targets: 4
2025-11-09
Number of reports: 41
Distinct targets: 3
2025-11-10
Number of reports: 176
Distinct targets: 8
2025-11-11
Number of reports: 176
Distinct targets: 8
2025-11-12
Number of reports: 560
Distinct targets: 12
2025-11-13
Number of reports: 1064
Distinct targets: 31
2025-11-14
Number of reports: 80
Distinct targets: 8
2025-11-15
Number of reports: 48
Distinct targets: 5
2025-11-16
Number of reports: 48
Distinct targets: 5
2025-11-17
Number of reports: 1280
Distinct targets: 19
2025-11-18
Number of reports: 1280
Distinct targets: 19
2025-11-19
Number of reports: 144
Distinct targets: 11
2025-11-20
Number of reports: 144
Distinct targets: 11
2025-11-21
Number of reports: 1479
Distinct targets: 39
2025-11-22
Number of reports: 552
Distinct targets: 24
2025-11-23
Number of reports: 40
Distinct targets: 5
2025-12-03
Number of reports: 56
Distinct targets: 6
2025-12-04
Number of reports: 48
Distinct targets: 5
2025-12-08
Number of reports: 280
Distinct targets: 18
Origin AS
AS13335 - CLOUDFLARENET
BGP Prefix
104.28.239.0/24
geo
Germany, Leipzig
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
104.16.0.0 - 104.31.255.255
reserved_range
0
ts_added
2025-10-28 05:05:51.473000
ts_last_update
2025-12-15 05:07:00.720000

Warden event timeline

DShield event timeline

Presence on blacklists