IP address


.00020.84.78.208
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
20.84.78.208 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-03-31 02:50:01.016000
Was present on blacklist at: 2025-03-21 03:50, 2025-03-22 03:50, 2025-03-23 03:50, 2025-03-24 03:50, 2025-03-25 03:50, 2025-03-26 03:50, 2025-03-27 03:50, 2025-03-28 03:50, 2025-03-29 03:50, 2025-03-30 02:50, 2025-03-31 02:50
Warden events (29)
2025-03-26
ReconScanning (node.4dc198): 2
ReconScanning (node.368407): 1
2025-03-25
ReconScanning (node.368407): 1
ReconScanning (node.4dc198): 1
2025-03-24
ReconScanning (node.4dc198): 2
AttemptLogin (node.9c160c): 1
ReconScanning (node.368407): 3
2025-03-23
ReconScanning (node.368407): 5
ReconScanning (node.4dc198): 3
2025-03-22
ReconScanning (node.368407): 2
ReconScanning (node.4dc198): 2
2025-03-21
ReconScanning (node.368407): 5
2025-03-20
ReconScanning (node.4dc198): 1
DShield reports (IP summary, reports)
2025-03-20
Number of reports: 13
Distinct targets: 12
2025-03-21
Number of reports: 53
Distinct targets: 46
2025-03-22
Number of reports: 145
Distinct targets: 89
2025-03-23
Number of reports: 133
Distinct targets: 103
2025-03-24
Number of reports: 159
Distinct targets: 104
2025-03-25
Number of reports: 57
Distinct targets: 53
2025-03-26
Number of reports: 62
Distinct targets: 52
OTX pulses
[606d75c11c08ff94089a9430] 2021-04-07 09:05:05.353000 | Georgs Honeypot
Author name:georgengelmann
Pulse modified:2025-04-23 03:00:40.083000
Indicator created:2025-03-24 07:01:03
Indicator role:bruteforce
Indicator title:SSH intrusion attempt from azpdeg8h5u2y.stretchoid.com port 57478
Indicator expiration:2025-04-23 07:00:00
Origin AS
AS8075 - MICROSOFT-CORP-MSN-AS-BLOCK
BGP Prefix
20.64.0.0/10
geo
United States, Washington
🕑 America/New_York
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
20.64.0.0 - 20.127.255.255
last_activity
2025-04-23 04:39:02.436000
last_warden_event
2025-03-26 08:46:59
rep
0.0
reserved_range
0
ts_added
2025-03-20 21:31:57.066000
ts_last_update
2025-05-01 21:32:00.535000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses