IP address
Tags:
Research scanner
Whitelisted
- IP blacklists
CI Army
109.105.209.85 is listed on the CI Army blacklist.
Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed:
primary (
feed detail page)
Last checked at:
2025-12-14 03:50:01.107000
Was present on blacklist at:
2025-10-17 02:50,
2025-10-18 02:50,
2025-10-19 02:50,
2025-10-20 02:50,
2025-10-21 02:50,
2025-10-22 02:50,
2025-10-23 02:50,
2025-10-24 02:50,
2025-10-26 03:50,
2025-10-27 03:50,
2025-10-29 03:50,
2025-11-01 03:50,
2025-11-02 03:50,
2025-11-03 03:50,
2025-11-05 03:50,
2025-11-06 03:50,
2025-11-07 03:50,
2025-11-08 03:50,
2025-11-09 03:50,
2025-11-10 03:50,
2025-11-11 03:50,
2025-11-12 03:50,
2025-11-13 03:50,
2025-11-14 03:50,
2025-11-15 03:50,
2025-11-16 03:50,
2025-11-17 03:50,
2025-11-18 03:50,
2025-11-19 03:50,
2025-11-20 03:50,
2025-11-21 03:50,
2025-11-25 03:50,
2025-11-30 03:50,
2025-12-01 03:50,
2025-12-02 03:50,
2025-12-03 03:50,
2025-12-04 03:50,
2025-12-06 03:50,
2025-12-07 03:50,
2025-12-08 03:50,
2025-12-10 03:50,
2025-12-11 03:50,
2025-12-12 03:50,
2025-12-13 03:50,
2025-12-14 03:50
Turris greylist
109.105.209.85 is listed on the Turris greylist blacklist.
Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed:
primary (
feed detail page)
Last checked at:
2025-12-15 22:15:00.177000
Was present on blacklist at:
2025-10-17 21:15,
2025-10-20 21:15,
2025-10-26 22:15,
2025-11-03 22:15,
2025-11-14 22:15,
2025-11-18 22:15,
2025-11-22 22:15,
2025-12-15 22:15
- Warden events (6)
- 2025-12-16
-
-
IntrusionUserCompromise (node.cfb4f7): 3
- 2025-12-14
-
-
IntrusionUserCompromise (node.cfb4f7): 3
- DShield reports (IP summary, reports)
- 2025-11-19
- Number of reports: 11
- Distinct targets: 9
- 2025-11-20
- Number of reports: 11
- Distinct targets: 9
- 2025-11-21
- Number of reports: 18
- Distinct targets: 9
- 2025-11-24
- Number of reports: 20
- Distinct targets: 9
- 2025-11-25
- Number of reports: 20
- Distinct targets: 9
- 2025-11-27
- Number of reports: 18
- Distinct targets: 9
- 2025-11-28
- Number of reports: 10
- Distinct targets: 6
- 2025-11-29
- Number of reports: 10
- Distinct targets: 6
- 2025-11-30
- Number of reports: 16
- Distinct targets: 8
- 2025-12-01
- Number of reports: 15
- Distinct targets: 15
- 2025-12-02
- Number of reports: 15
- Distinct targets: 15
- 2025-12-04
- Number of reports: 12
- Distinct targets: 11
- 2025-12-09
- Number of reports: 14
- Distinct targets: 6
- 2025-12-10
- Number of reports: 12
- Distinct targets: 7
- Origin AS
- AS21859 - ZNET
- BGP Prefix
- 109.105.209.0/24
- geo
-
Portugal
- 🕑 Europe/Lisbon
- hostname
- zl-laxk-us-gp7-wk123d.internet-census.org
- hostname_class
- ['research_scanner']
- Address block ('inetnum' or 'NetRange' in whois database)
- 109.105.208.0 - 109.105.215.255
- last_activity
- 2025-12-16 11:48:29
- last_warden_event
- 2025-12-16 11:48:29
- rep
- 0.10833333333333334
- reserved_range
- 0
- ts_added
- 2025-10-17 02:51:16.427000
- ts_last_update
- 2025-12-16 11:48:42.170000
Warden event timeline
DShield event timeline
Presence on blacklists