IP address


.35623.139.36.16
Shodan(more info)
Passive DNS
Tags:
IP blacklists
UCEPROTECT L1
23.139.36.16 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-10-02 23:45:00.677000
Was present on blacklist at: 2026-08-25 07:45, 2026-08-25 15:45, 2026-08-25 23:45, 2026-08-26 07:45, 2026-08-26 15:45, 2026-08-26 23:45, 2026-08-27 07:45, 2026-08-27 15:45, 2026-08-27 23:45, 2026-08-28 07:45, 2026-08-28 15:45, 2026-08-28 23:45, 2026-08-29 07:45, 2026-08-29 15:45, 2026-08-29 23:45, 2026-08-30 07:45, 2026-08-30 23:45, 2026-08-31 07:45, 2026-08-31 15:45, 2026-08-31 23:45, 2026-09-01 15:45, 2026-09-01 23:45, 2026-09-02 07:45, 2026-09-02 15:45, 2026-09-02 23:45, 2026-09-03 23:45, 2026-09-04 07:45, 2026-09-04 15:45, 2026-09-04 23:45, 2026-09-05 07:45, 2026-09-05 15:45, 2026-09-05 23:45, 2026-09-06 07:45, 2026-09-06 23:45, 2026-09-07 15:45, 2026-09-07 23:45, 2026-09-08 07:45, 2026-09-11 23:45, 2026-09-12 07:45, 2026-09-12 23:45, 2026-09-13 07:45, 2026-09-13 15:45, 2026-09-13 23:45, 2026-09-14 07:45, 2026-09-14 15:45, 2026-09-14 23:45, 2026-09-15 15:45, 2026-09-15 23:45, 2026-09-16 07:45, 2026-09-16 15:45, 2026-09-16 23:45, 2026-09-17 07:45, 2026-09-17 15:45, 2026-09-17 23:45, 2026-09-18 07:45, 2026-09-18 15:45, 2026-09-27 07:45, 2026-09-27 15:45, 2026-09-27 23:45, 2026-09-28 07:45, 2026-09-28 15:45, 2026-09-28 23:45, 2026-09-29 07:45, 2026-09-29 15:45, 2026-09-29 23:45, 2026-09-30 07:45, 2026-09-30 15:45, 2026-09-30 23:45, 2026-10-01 07:45, 2026-10-01 15:45, 2026-10-01 23:45, 2026-10-02 07:45, 2026-10-02 15:45, 2026-10-02 23:45
Echelon port scan
23.139.36.16 was recently listed on the Echelon port scan blacklist, but currently it is not.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning 5+ ports on target host
Type of feed: primary (feed detail page)

Last checked at: 2026-10-01 09:25:00.582000
Was present on blacklist at: 2026-08-26 09:25, 2026-08-27 09:25, 2026-08-28 09:25, 2026-08-29 09:25, 2026-08-30 09:25, 2026-08-31 09:25, 2026-09-01 09:25, 2026-09-26 09:25, 2026-09-27 09:25, 2026-09-28 09:25, 2026-09-29 09:25, 2026-09-30 09:25, 2026-10-01 09:25
CI Army
23.139.36.16 was recently listed on the CI Army blacklist, but currently it is not.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-10-01 02:50:00.755000
Was present on blacklist at: 2026-08-27 02:50, 2026-08-28 02:50, 2026-08-29 02:50, 2026-09-01 02:50, 2026-09-02 02:50, 2026-09-03 02:50, 2026-09-04 02:50, 2026-09-06 02:50, 2026-09-08 02:50, 2026-09-09 02:50, 2026-09-10 02:50, 2026-09-11 02:50, 2026-09-19 02:50, 2026-09-20 02:50, 2026-09-21 02:50, 2026-09-22 02:50, 2026-09-23 02:50, 2026-09-24 02:50, 2026-09-25 02:50, 2026-09-26 02:50, 2026-09-27 02:50, 2026-09-28 02:50, 2026-09-29 02:50, 2026-09-30 02:50, 2026-10-01 02:50
AbuseIPDB
23.139.36.16 was recently listed on the AbuseIPDB blacklist, but currently it is not.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-22 04:00:00.583000
Was present on blacklist at: 2026-09-04 04:00, 2026-09-08 04:00, 2026-09-09 04:00, 2026-09-19 04:00, 2026-09-22 04:00
Spamhaus XBL CBL
23.139.36.16 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-10-01 20:22:00.467000
Was present on blacklist at: 2026-09-24 20:22, 2026-10-01 20:22

Threat categories

TLRoleCategoryDetails
64 src scan
40 src —

Warden events (427)
2026-09-29
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 1
2026-09-28
ReconScanning (node.368407): 24
ReconScanning (node.4dc198): 24
ReconScanning (node.f90c6b): 11
ReconScanning (node.86eb21): 4
2026-09-27
ReconScanning (node.86eb21): 1
ReconScanning (node.4dc198): 2
ReconScanning (node.368407): 3
2026-09-25
ReconScanning (node.368407): 39
ReconScanning (node.f90c6b): 26
2026-09-24
ReconScanning (node.368407): 25
ReconScanning (node.f90c6b): 10
ReconScanning (node.86eb21): 6
2026-09-23
ReconScanning (node.86eb21): 4
2026-09-22
ReconScanning (node.86eb21): 5
2026-09-19
ReconScanning (node.368407): 21
ReconScanning (node.f90c6b): 22
2026-09-11
AnomalyTraffic (node.ce2b59): 2
AnomalyTraffic (node.6a1878): 1
ReconScanning (node.ce2b59): 2
ReconScanning (node.4dc198): 5
2026-09-06
ReconScanning (node.86eb21): 7
2026-09-04
AnomalyTraffic (node.ce2b59): 9
ReconScanning (node.ce2b59): 3
AnomalyTraffic (node.6a1878): 3
ReconScanning (node.4dc198): 30
ReconScanning (node.86eb21): 16
2026-09-02
ReconScanning (node.86eb21): 1
2026-08-27
ReconScanning (node.86eb21): 1
2026-08-25
ReconScanning (node.86eb21): 1
2026-08-23
ReconScanning (node.86eb21): 10
2026-08-22
AnomalyTraffic (node.6a1878): 3
AnomalyTraffic (node.ce2b59): 9
ReconScanning (node.ce2b59): 5
ReconScanning (node.4dc198): 22
ReconScanning (node.86eb21): 35
2026-08-21
ReconScanning (node.86eb21): 5
ReconScanning (node.4dc198): 8
2026-08-20
ReconScanning (node.86eb21): 4
ReconScanning (node.4dc198): 16
DShield reports (IP summary, reports)
2026-08-24
Number of reports: 1137
Distinct targets: 987
2026-08-25
Number of reports: 1137
Distinct targets: 987
2026-08-26
Number of reports: 300
Distinct targets: 150
2026-08-27
Number of reports: 863
Distinct targets: 713
2026-08-28
Number of reports: 82
Distinct targets: 45
2026-09-01
Number of reports: 300
Distinct targets: 150
2026-09-02
Number of reports: 300
Distinct targets: 150
2026-09-03
Number of reports: 300
Distinct targets: 300
2026-09-04
Number of reports: 450
Distinct targets: 300
2026-09-05
Number of reports: 600
Distinct targets: 450
2026-09-06
Number of reports: 213
Distinct targets: 150
2026-09-07
Number of reports: 213
Distinct targets: 150
2026-09-08
Number of reports: 393
Distinct targets: 272
2026-09-09
Number of reports: 1038
Distinct targets: 944
2026-09-10
Number of reports: 474
Distinct targets: 474
2026-09-11
Number of reports: 474
Distinct targets: 474
2026-09-12
Number of reports: 442
Distinct targets: 442
2026-09-20
Number of reports: 849
Distinct targets: 449
2026-09-21
Number of reports: 565
Distinct targets: 414
2026-09-22
Number of reports: 604
Distinct targets: 453
2026-09-23
Number of reports: 1735
Distinct targets: 1245
2026-09-24
Number of reports: 2173
Distinct targets: 1480
2026-09-25
Number of reports: 2173
Distinct targets: 1480
2026-09-26
Number of reports: 782
Distinct targets: 631
2026-09-27
Number of reports: 782
Distinct targets: 631
2026-09-28
Number of reports: 60
Distinct targets: 60
2026-09-29
Number of reports: 30
Distinct targets: 18
Origin AS
AS63023 - AS-GLOBALTELEHOST
BGP Prefix
23.139.36.0/24
geo
United States, Phoenix
🕑 America/Phoenix
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
23.139.33.0 - 23.139.47.255
last_activity
2026-09-29 07:11:34
last_warden_event
2026-09-29 07:11:34
rep
0.3556004338404969
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80, 443, 8090
Tags: –
CPEs: cpe:/a:golang:go, cpe:/a:caddyserver:caddy, cpe:/a:openbsd:openssh:9.6p1, cpe:/a:f5:nginx:1.31.4, cpe:/o:canonical:ubuntu_linux
ts_added
2026-08-20 20:21:57.931000
ts_last_update
2026-10-02 23:58:42.872000

Warden event timeline

DShield event timeline

Presence on blacklists