IP address


.000204.194.48.250
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL
204.194.48.250 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-07-30 17:03:30.285000
Was present on blacklist at: 2026-07-02 17:03, 2026-07-09 17:03, 2026-07-16 17:03, 2026-07-23 17:03, 2026-07-30 17:03
Spamhaus DROP
204.194.48.250 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-07-30 17:03:30.285000
Was present on blacklist at: 2026-07-02 17:03, 2026-07-09 17:03, 2026-07-16 17:03, 2026-07-23 17:03, 2026-07-30 17:03

Threat categories

TLRoleCategoryDetails
No threat category tags assigned

OTX pulses
[6a3e75975494e990e7421b4d] 2026-06-26 12:50:31.995000 | Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
Author name:AlienVault
Pulse modified:2026-06-26 17:48:29.047000
Indicator created:2026-06-26 12:50:32
Indicator role:None
Indicator title:
Indicator expiration:2026-07-26 12:00:00
Origin AS
AS140869 - TGL-AS-AP
BGP Prefix
204.194.48.0/24
geo
United States
🕑 America/Chicago
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
204.194.48.0 - 204.194.55.255
last_activity
2026-07-02 17:03:27.728000
rep
0.0
reserved_range
0
Shodan's InternetDB
Open ports: 80
Tags:
CPEs: cpe:/a:f5:nginx
ts_added
2026-07-02 17:03:27.738000
ts_last_update
2026-08-05 17:03:30.951000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses