IP address


.06650.3.85.90
Shodan(more info)
Passive DNS
Tags:
IP blacklists
CI Army
50.3.85.90 was recently listed on the CI Army blacklist, but currently it is not.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-09-26 02:50:00.808000
Was present on blacklist at: 2026-09-19 02:50, 2026-09-22 02:50, 2026-09-23 02:50, 2026-09-24 02:50, 2026-09-25 02:50, 2026-09-26 02:50
AbuseIPDB
50.3.85.90 was recently listed on the AbuseIPDB blacklist, but currently it is not.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 04:00:00.712000
Was present on blacklist at: 2026-09-20 04:00, 2026-09-27 04:00, 2026-09-28 04:00

Threat categories

TLRoleCategoryDetails
68 src scan port: 123, 389, 523
31 src —

Warden events (233)
2026-09-28
ReconScanning (node.ce2b59): 10
2026-09-26
ReconScanning (node.ce2b59): 10
2026-09-23
ReconScanning (node.ce2b59): 5
AnomalyTraffic (node.ce2b59): 59
2026-09-21
ReconScanning (node.ce2b59): 17
AnomalyTraffic (node.ce2b59): 85
2026-09-20
ReconScanning (node.ce2b59): 6
2026-09-18
ReconScanning (node.ce2b59): 14
AnomalyTraffic (node.6a1878): 1
2026-09-17
ReconScanning (node.ce2b59): 18
2026-09-16
ReconScanning (node.ce2b59): 8
DShield reports (IP summary, reports)
2026-09-16
Number of reports: 112
Distinct targets: 77
2026-09-17
Number of reports: 578
Distinct targets: 402
2026-09-18
Number of reports: 624
Distinct targets: 463
2026-09-19
Number of reports: 624
Distinct targets: 463
2026-09-20
Number of reports: 357
Distinct targets: 236
2026-09-21
Number of reports: 643
Distinct targets: 465
2026-09-23
Number of reports: 328
Distinct targets: 250
2026-09-26
Number of reports: 339
Distinct targets: 231
2026-09-27
Number of reports: 339
Distinct targets: 231
2026-09-28
Number of reports: 317
Distinct targets: 235
Origin AS
AS49532 - SERVERHUB-DE
BGP Prefix
50.3.84.0/22
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
50.2.0.0 - 50.3.255.255
last_activity
2026-09-28 14:17:12
last_warden_event
2026-09-28 14:17:12
rep
0.0660471534837953
reserved_range
0
Shodan's InternetDB
Open ports: 80
Tags: –
CPEs: cpe:/a:apache:http_server:2.4.37
ts_added
2026-09-16 06:59:17.493000
ts_last_update
2026-10-02 06:59:20.249000

Warden event timeline

DShield event timeline

Presence on blacklists