IP address


--172.110.223.27
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Echelon SIP register scanner
172.110.223.27 is listed on the Echelon SIP register scanner blacklist.

Description: SIP VoIP registration scanning on port 5060
Type of feed: primary (feed detail page)

Last checked at: 2026-04-01 09:30:00.776000
Was present on blacklist at: 2026-03-23 10:30, 2026-03-24 10:30, 2026-03-25 10:30, 2026-03-26 10:30, 2026-03-27 10:30, 2026-03-28 10:30, 2026-03-29 09:30, 2026-03-30 09:30, 2026-03-31 09:30, 2026-04-01 09:30
UCEPROTECT L1
172.110.223.27 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-03-31 15:45:01.369000
Was present on blacklist at: 2026-03-25 00:45, 2026-03-25 08:45, 2026-03-25 16:45, 2026-03-26 00:45, 2026-03-26 08:45, 2026-03-26 16:45, 2026-03-27 00:45, 2026-03-27 08:45, 2026-03-27 16:45, 2026-03-28 00:45, 2026-03-28 08:45, 2026-03-28 16:45, 2026-03-29 00:45, 2026-03-29 07:45, 2026-03-29 15:45, 2026-03-29 23:45, 2026-03-30 07:45, 2026-03-30 15:45, 2026-03-30 23:45, 2026-03-31 07:45, 2026-03-31 15:45
CI Army
172.110.223.27 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-03-30 02:50:00.950000
Was present on blacklist at: 2026-03-26 03:50, 2026-03-27 03:50, 2026-03-28 03:50, 2026-03-29 02:50, 2026-03-30 02:50
AbuseIPDB
172.110.223.27 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-03-29 04:00:00.556000
Was present on blacklist at: 2026-03-26 05:00, 2026-03-29 04:00

Threat categories

TLRoleCategoryDetails
45 src
44 src scan

DShield reports (IP summary, reports)
2026-03-22
Number of reports: 53
Distinct targets: 18
2026-03-23
Number of reports: 117
Distinct targets: 34
2026-03-24
Number of reports: 117
Distinct targets: 34
2026-03-25
Number of reports: 97
Distinct targets: 40
2026-03-26
Number of reports: 97
Distinct targets: 40
2026-03-28
Number of reports: 17
Distinct targets: 9
2026-03-29
Number of reports: 17
Distinct targets: 9
Origin AS
AS23470 - RELIABLESITE
AS47154 - HUSAM-Network
BGP Prefix
172.110.223.0/24
geo
Hong Kong
🕑 Asia/Hong_Kong
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
172.110.208.0 - 172.110.223.255
reserved_range
0
Shodan's InternetDB
Open ports: 80, 3389
Tags: self-signed
CPEs: cpe:/o:microsoft:windows, cpe:/a:microsoft:internet_information_services:10.0
ts_added
2026-03-23 05:00:59.924000
ts_last_update
2026-04-06 05:01:04.729000

Warden event timeline

DShield event timeline

Presence on blacklists