IP address


.296165.154.2.94
Shodan(more info)
Passive DNS
Tags: Scanner Login attempts
IP blacklists
Spamhaus SBL
165.154.2.94 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-06-03 01:52:03.616000
Was present on blacklist at: 2026-04-29 01:51, 2026-05-06 01:52, 2026-05-13 01:52, 2026-05-20 01:52, 2026-05-27 01:52, 2026-06-03 01:52
spamhaus-pbl
165.154.2.94 is listed on the spamhaus-pbl blacklist.

Description:
Type of feed: (feed detail page)

Last checked at: 2026-06-03 01:52:03.616000
Was present on blacklist at: 2026-04-29 01:51, 2026-05-06 01:52, 2026-05-13 01:52, 2026-05-20 01:52, 2026-05-27 01:52, 2026-06-03 01:52
UCEPROTECT L1
165.154.2.94 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-05-16 15:45:00.558000
Was present on blacklist at: 2026-05-09 23:45, 2026-05-10 15:45, 2026-05-10 23:45, 2026-05-11 07:45, 2026-05-11 15:45, 2026-05-11 23:45, 2026-05-12 07:45, 2026-05-12 15:45, 2026-05-12 23:45, 2026-05-13 07:45, 2026-05-13 15:45, 2026-05-13 23:45, 2026-05-14 07:45, 2026-05-14 15:45, 2026-05-14 23:45, 2026-05-15 07:45, 2026-05-15 15:45, 2026-05-15 23:45, 2026-05-16 07:45, 2026-05-16 15:45

Threat categories

TLRoleCategoryDetails
26 src scan port: many

Warden events (438)
2026-06-01
ReconScanning (node.ce2b59): 1
2026-05-30
ReconScanning (node.ce2b59): 1
2026-05-22
ReconScanning (node.ce2b59): 4
2026-05-21
AttemptLogin (node.b17ef8): 135
ReconScanning (node.ce2b59): 13
2026-05-20
AttemptLogin (node.b17ef8): 18
2026-05-19
ReconScanning (node.ce2b59): 1
2026-05-16
ReconScanning (node.ce2b59): 17
2026-05-15
ReconScanning (node.ce2b59): 13
2026-05-14
ReconScanning (node.ce2b59): 13
2026-05-13
AttemptLogin (node.4dc198): 33
ReconScanning (node.ce2b59): 15
2026-05-12
ReconScanning (node.ce2b59): 22
AttemptLogin (node.4dc198): 26
2026-05-11
ReconScanning (node.ce2b59): 16
2026-05-10
ReconScanning (node.ce2b59): 20
2026-05-09
ReconScanning (node.ce2b59): 17
2026-05-08
ReconScanning (node.ce2b59): 18
ReconScanning (node.9c1411): 1
2026-05-07
ReconScanning (node.ce2b59): 18
2026-05-06
ReconScanning (node.ce2b59): 21
2026-05-05
ReconScanning (node.ce2b59): 13
2026-04-27
AttemptLogin (node.4dc198): 2
DShield reports (IP summary, reports)
2026-05-02
Number of reports: 420
Distinct targets: 3
2026-05-03
Number of reports: 420
Distinct targets: 3
Origin AS
AS135377 - UHGL-AS-AP
BGP Prefix
165.154.2.0/24
geo
Hong Kong, Hong Kong
🕑 Asia/Hong_Kong
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
165.154.0.0 - 165.154.127.255
last_activity
2026-06-01 01:12:33
last_warden_event
2026-06-01 01:12:33
rep
0.2960126056983675
reserved_range
0
ts_added
2026-04-29 01:51:52.806000
ts_last_update
2026-06-04 01:52:00.357000

Warden event timeline

DShield event timeline

Presence on blacklists