IP address


--185.196.11.118
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
185.196.11.118 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-06-19 19:13:10.140000
Was present on blacklist at: 2025-03-27 19:13, 2025-04-03 19:13, 2025-04-10 19:13, 2025-04-17 19:13, 2025-04-24 19:13, 2025-05-01 19:13, 2025-05-08 19:13, 2025-05-15 19:13, 2025-05-22 19:13, 2025-05-29 19:13, 2025-06-05 19:13, 2025-06-12 19:13, 2025-06-19 19:13
Spamhaus XBL CBL
185.196.11.118 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-06-19 19:13:10.140000
Was present on blacklist at: 2025-04-10 19:13, 2025-04-17 19:13, 2025-05-15 19:13, 2025-05-22 19:13
Spamhaus DROP
185.196.11.118 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-06-19 19:13:10.140000
Was present on blacklist at: 2025-03-27 19:13, 2025-04-03 19:13, 2025-04-10 19:13, 2025-04-17 19:13, 2025-04-24 19:13, 2025-05-01 19:13, 2025-05-08 19:13, 2025-05-15 19:13, 2025-05-22 19:13, 2025-05-29 19:13, 2025-06-05 19:13, 2025-06-12 19:13, 2025-06-19 19:13
blocklist.de SSH
185.196.11.118 is listed on the blocklist.de SSH blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2025-05-03 22:05:05.353000
Was present on blacklist at: 2025-03-24 23:05, 2025-03-25 05:05, 2025-03-25 11:05, 2025-03-25 17:05, 2025-03-25 23:05, 2025-03-26 05:05, 2025-03-26 11:05, 2025-03-26 17:05, 2025-03-31 04:05, 2025-03-31 10:05, 2025-03-31 16:05, 2025-03-31 22:05, 2025-04-01 04:05, 2025-04-01 10:05, 2025-04-01 16:05, 2025-04-01 22:05, 2025-04-02 04:05, 2025-04-02 10:05, 2025-04-02 16:05, 2025-05-01 22:05, 2025-05-02 04:05, 2025-05-02 10:05, 2025-05-02 16:05, 2025-05-02 22:05, 2025-05-03 04:05, 2025-05-03 10:05, 2025-05-03 16:05, 2025-05-03 22:05
AbuseIPDB
185.196.11.118 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-06-19 04:00:00.677000
Was present on blacklist at: 2025-04-02 04:00, 2025-04-16 04:00, 2025-04-25 04:00, 2025-04-26 04:00, 2025-04-28 04:00, 2025-05-01 04:00, 2025-05-24 04:00, 2025-05-29 04:00, 2025-05-31 04:00, 2025-06-06 04:00, 2025-06-09 04:00, 2025-06-10 04:00, 2025-06-11 04:00, 2025-06-12 04:00, 2025-06-13 04:00, 2025-06-14 04:00, 2025-06-15 04:00, 2025-06-16 04:00, 2025-06-17 04:00, 2025-06-18 04:00, 2025-06-19 04:00
UCEPROTECT L1
185.196.11.118 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-06-19 15:45:00.822000
Was present on blacklist at: 2025-03-22 00:45, 2025-03-22 08:45, 2025-03-22 16:45, 2025-03-23 00:45, 2025-03-23 08:45, 2025-03-23 16:45, 2025-03-24 00:45, 2025-03-24 08:45, 2025-03-24 16:45, 2025-03-29 08:45, 2025-03-29 16:45, 2025-03-30 00:45, 2025-03-30 07:45, 2025-03-30 15:45, 2025-03-30 23:45, 2025-03-31 07:45, 2025-03-31 15:45, 2025-03-31 23:45, 2025-04-01 07:45, 2025-04-01 15:45, 2025-04-01 23:45, 2025-04-02 07:45, 2025-04-02 15:45, 2025-04-02 23:45, 2025-04-03 07:45, 2025-04-03 15:45, 2025-04-03 23:45, 2025-04-04 07:45, 2025-04-04 15:45, 2025-04-04 23:45, 2025-04-05 07:45, 2025-04-05 15:45, 2025-04-05 23:45, 2025-04-06 07:45, 2025-04-06 15:45, 2025-04-06 23:45, 2025-04-07 07:45, 2025-04-07 15:45, 2025-04-07 23:45, 2025-04-08 07:45, 2025-04-08 15:45, 2025-04-08 23:45, 2025-04-09 07:45, 2025-04-30 23:45, 2025-05-01 07:45, 2025-05-01 15:45, 2025-05-01 23:45, 2025-05-02 07:45, 2025-05-02 15:45, 2025-05-02 23:45, 2025-05-03 07:45, 2025-05-03 15:45, 2025-05-03 23:45, 2025-05-04 07:45, 2025-05-04 15:45, 2025-05-04 23:45, 2025-05-05 07:45, 2025-05-05 15:45, 2025-05-05 23:45, 2025-05-06 07:45, 2025-05-06 15:45, 2025-05-06 23:45, 2025-05-07 07:45, 2025-05-07 15:45, 2025-05-07 23:45, 2025-05-08 07:45, 2025-05-08 15:45, 2025-05-08 23:45, 2025-05-09 07:45, 2025-05-09 15:45, 2025-05-09 23:45, 2025-05-10 07:45, 2025-05-10 15:45, 2025-05-10 23:45, 2025-05-11 07:45, 2025-05-11 15:45, 2025-05-11 23:45, 2025-05-12 07:45, 2025-05-12 15:45, 2025-05-12 23:45, 2025-05-13 07:45, 2025-05-13 15:45, 2025-05-13 23:45, 2025-06-13 07:45, 2025-06-13 15:45, 2025-06-13 23:45, 2025-06-14 07:45, 2025-06-14 15:45, 2025-06-14 23:45, 2025-06-15 07:45, 2025-06-15 15:45, 2025-06-15 23:45, 2025-06-16 07:45, 2025-06-16 15:45, 2025-06-16 23:45, 2025-06-17 07:45, 2025-06-17 15:45, 2025-06-17 23:45, 2025-06-18 07:45, 2025-06-18 15:45, 2025-06-18 23:45, 2025-06-19 07:45, 2025-06-19 15:45
blocklist.de IMAP
185.196.11.118 is listed on the blocklist.de IMAP blacklist.

Description: Blocklist.de feed is a free and voluntary service<br>provided by a Fraud/Abuse-specialist. IPs performing attacks<br>on the Service imap, sasl, pop3.
Type of feed: primary (feed detail page)

Last checked at: 2025-03-24 17:05:00.332000
Was present on blacklist at: 2025-03-24 11:05, 2025-03-24 17:05
blocklist.de mail
185.196.11.118 is listed on the blocklist.de mail blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing Mail attacks.
Type of feed: primary (feed detail page)

Last checked at: 2025-03-24 17:05:00.419000
Was present on blacklist at: 2025-03-24 11:05, 2025-03-24 17:05
DShield reports (IP summary, reports)
2025-03-27
Number of reports: 111
Distinct targets: 103
2025-03-28
Number of reports: 40
Distinct targets: 38
2025-03-29
Number of reports: 220
Distinct targets: 219
2025-04-02
Number of reports: 43
Distinct targets: 43
2025-04-03
Number of reports: 54
Distinct targets: 54
2025-04-09
Number of reports: 225
Distinct targets: 109
2025-04-11
Number of reports: 28
Distinct targets: 12
2025-04-13
Number of reports: 46
Distinct targets: 42
2025-04-14
Number of reports: 29
Distinct targets: 29
2025-04-15
Number of reports: 39
Distinct targets: 35
2025-04-16
Number of reports: 97
Distinct targets: 45
2025-04-17
Number of reports: 96
Distinct targets: 44
2025-04-18
Number of reports: 90
Distinct targets: 42
2025-04-19
Number of reports: 272
Distinct targets: 253
2025-04-20
Number of reports: 482
Distinct targets: 285
2025-04-21
Number of reports: 187
Distinct targets: 105
2025-04-22
Number of reports: 67
Distinct targets: 59
2025-04-24
Number of reports: 119
Distinct targets: 48
2025-04-27
Number of reports: 111
Distinct targets: 108
2025-04-28
Number of reports: 324
Distinct targets: 239
2025-04-29
Number of reports: 45
Distinct targets: 39
2025-05-01
Number of reports: 146
Distinct targets: 74
2025-05-05
Number of reports: 66
Distinct targets: 31
2025-05-09
Number of reports: 92
Distinct targets: 40
2025-05-20
Number of reports: 91
Distinct targets: 39
2025-05-22
Number of reports: 13
Distinct targets: 6
2025-05-24
Number of reports: 60
Distinct targets: 30
2025-05-25
Number of reports: 49
Distinct targets: 49
2025-05-26
Number of reports: 127
Distinct targets: 73
2025-05-28
Number of reports: 70
Distinct targets: 70
2025-05-29
Number of reports: 25
Distinct targets: 13
2025-05-30
Number of reports: 40
Distinct targets: 40
2025-05-31
Number of reports: 12
Distinct targets: 6
2025-06-01
Number of reports: 14
Distinct targets: 14
2025-06-03
Number of reports: 261
Distinct targets: 255
2025-06-04
Number of reports: 24
Distinct targets: 6
2025-06-11
Number of reports: 16
Distinct targets: 3
2025-06-16
Number of reports: 62
Distinct targets: 58
Origin AS
AS42624 - simplecarrier
BGP Prefix
185.196.11.0/24
geo
Switzerland
🕑 Europe/Zurich
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
185.196.8.0 - 185.196.11.255
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags:
CPEs: cpe:/a:openbsd:openssh:9.2p1, cpe:/o:debian:debian_linux, cpe:/o:linux:linux_kernel
ts_added
2025-02-06 19:13:03.868000
ts_last_update
2025-06-19 19:13:10.420000

Warden event timeline

DShield event timeline

Presence on blacklists