IP address


--109.205.213.3
Shodan(more info)
Passive DNS
Tags:
IP blacklists
CI Army
109.205.213.3 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-12-07 03:50:01.021000
Was present on blacklist at: 2025-11-24 03:50, 2025-11-25 03:50, 2025-11-26 03:50, 2025-11-27 03:50, 2025-11-28 03:50, 2025-11-29 03:50, 2025-11-30 03:50, 2025-12-01 03:50, 2025-12-02 03:50, 2025-12-03 03:50, 2025-12-04 03:50, 2025-12-05 03:50, 2025-12-06 03:50, 2025-12-07 03:50
Spamhaus PBL ISP
109.205.213.3 was recently listed on the Spamhaus PBL ISP blacklist, but currently it is not.

Description: The Spamhaus PBL is a DNSBL database of end-user IP address ranges which should not be delivering unauthenticated SMTP email to any Internet mail server except those provided for specifically by an ISP for that customer's use.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-15 03:54:35.098000
Was present on blacklist at: 2025-11-24 03:54
AbuseIPDB
109.205.213.3 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-12-04 05:00:00.704000
Was present on blacklist at: 2025-11-24 05:00, 2025-11-25 05:00, 2025-11-26 05:00, 2025-11-27 05:00, 2025-11-28 05:00, 2025-11-29 05:00, 2025-11-30 05:00, 2025-12-01 05:00, 2025-12-02 05:00, 2025-12-03 05:00, 2025-12-04 05:00
Turris greylist
109.205.213.3 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-03 22:15:00.181000
Was present on blacklist at: 2025-11-25 22:15, 2025-11-30 22:15, 2025-12-03 22:15
DShield reports (IP summary, reports)
2025-11-23
Number of reports: 4272
Distinct targets: 2808
2025-11-24
Number of reports: 4234
Distinct targets: 2823
2025-11-25
Number of reports: 4234
Distinct targets: 2823
2025-11-26
Number of reports: 3639
Distinct targets: 2639
2025-11-27
Number of reports: 3873
Distinct targets: 2611
2025-11-28
Number of reports: 3938
Distinct targets: 2679
2025-11-29
Number of reports: 3938
Distinct targets: 2679
2025-11-30
Number of reports: 3838
Distinct targets: 2594
2025-12-01
Number of reports: 2831
Distinct targets: 2016
2025-12-02
Number of reports: 2831
Distinct targets: 2016
2025-12-03
Number of reports: 3786
Distinct targets: 2636
2025-12-04
Number of reports: 2276
Distinct targets: 1650
Origin AS
AS19318 - NJIIX-AS-1
AS23470 - RELIABLESITE
BGP Prefix
109.205.213.0/24
geo
Azerbaijan
🕑 Asia/Baku
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
109.205.208.0 - 109.205.215.255
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags:
CPEs: cpe:/a:openbsd:openssh:8.2p1, cpe:/o:canonical:ubuntu_linux
ts_added
2025-11-24 03:54:28.195000
ts_last_update
2025-12-18 03:54:31.938000

Warden event timeline

DShield event timeline

Presence on blacklists