IP address


--172.104.5.80172-104-5-80.ip.linodeusercontent.com
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
DataPlane SMTP greeting
172.104.5.80 is listed on the DataPlane SMTP greeting blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs that are<br>identified as SMTP clients issuing unsolicited HELO or EHLO commands.
Type of feed: primary (feed detail page)

Last checked at: 2025-04-22 10:10:00.997000
Was present on blacklist at: 2025-04-15 22:10, 2025-04-16 02:10, 2025-04-16 06:10, 2025-04-16 10:10, 2025-04-16 14:10, 2025-04-16 18:10, 2025-04-16 22:10, 2025-04-17 02:10, 2025-04-17 06:10, 2025-04-17 10:10, 2025-04-17 14:10, 2025-04-17 18:10, 2025-04-17 22:10, 2025-04-18 02:10, 2025-04-18 06:10, 2025-04-18 10:10, 2025-04-18 14:10, 2025-04-18 18:10, 2025-04-18 22:10, 2025-04-19 02:10, 2025-04-19 06:10, 2025-04-19 10:10, 2025-04-19 14:10, 2025-04-19 18:10, 2025-04-19 22:10, 2025-04-20 02:10, 2025-04-20 06:10, 2025-04-20 10:10, 2025-04-20 14:10, 2025-04-20 18:10, 2025-04-20 22:10, 2025-04-21 02:10, 2025-04-21 06:10, 2025-04-21 10:10, 2025-04-21 14:10, 2025-04-21 18:10, 2025-04-21 22:10, 2025-04-22 02:10, 2025-04-22 06:10, 2025-04-22 10:10
Spamhaus SBL CSS
172.104.5.80 was recently listed on the Spamhaus SBL CSS blacklist, but currently it is not.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-04-22 22:12:30.048000
Was present on blacklist at: 2025-04-15 22:12
Spamhaus XBL CBL
172.104.5.80 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-04-22 22:12:30.048000
Was present on blacklist at: 2025-04-15 22:12
DShield reports (IP summary, reports)
2025-04-15
Number of reports: 22
Distinct targets: 22
Origin AS
AS63949 - LINODE-AP
BGP Prefix
172.104.4.0/22
geo
United States, Cedar Knolls
🕑 America/New_York
hostname
172-104-5-80.ip.linodeusercontent.com
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
172.104.0.0 - 172.105.255.255
reserved_range
0
Shodan's InternetDB
Open ports: 22, 10000, 10045, 10051, 10533, 11112, 11180, 11288, 11920, 12110, 12126, 12141, 12225, 12337, 12375, 12404, 12415, 12427, 12474, 12524, 12551, 12572, 13579, 14026, 14082, 14147, 14905, 15504, 16033, 16051, 16054, 16077, 16092, 16400, 17000, 17102, 18024, 18060, 18063, 18080, 18245, 19000, 19071, 19091, 19200, 20060, 20443, 20547, 20900, 21025, 21027, 21082, 21242, 21248, 21263, 21266, 21281, 21308, 21310, 21312, 21329, 21379, 22001, 22070, 23023, 24245, 25003, 29842, 30001, 30003, 30005, 30021, 30122, 30222, 30322, 30422, 30522, 30622, 30822, 30922, 31022, 31322, 31422, 31522, 31622, 31822, 32022, 32122, 32400, 32422, 32622, 32722, 32764, 33060, 37777, 39001, 44332, 45821, 49152, 49153, 50004, 50101, 50106, 50113, 51003, 53200, 54022, 54138, 54857, 55554
Tags: cloud
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.9p1
ts_added
2025-04-15 22:12:22.834000
ts_last_update
2025-04-27 22:12:30.867000

Warden event timeline

DShield event timeline

Presence on blacklists