IP address


.02472.201.104.156ip72-201-104-156.ph.ph.cox.net
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
CI Army
72.201.104.156 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-12-12 03:50:00.954000
Was present on blacklist at: 2025-10-30 03:50, 2025-10-31 03:50, 2025-11-01 03:50, 2025-11-11 03:50, 2025-11-13 03:50, 2025-11-29 03:50, 2025-11-30 03:50, 2025-12-01 03:50, 2025-12-02 03:50, 2025-12-03 03:50, 2025-12-11 03:50, 2025-12-12 03:50
Warden events (9)
2025-12-08
ReconScanning (node.368407): 2
2025-12-03
ReconScanning (node.368407): 1
2025-12-01
ReconScanning (node.368407): 5
2025-10-29
ReconScanning (node.368407): 1
DShield reports (IP summary, reports)
2025-11-09
Number of reports: 37
Distinct targets: 24
2025-11-17
Number of reports: 12
Distinct targets: 6
2025-11-18
Number of reports: 12
Distinct targets: 6
2025-12-05
Number of reports: 20
Distinct targets: 10
Origin AS
AS22773 - ASN-CXA-ALL-CCI-22773-RDC
BGP Prefix
72.201.0.0/16
geo
United States, Phoenix
🕑 America/Phoenix
hostname
ip72-201-104-156.ph.ph.cox.net
hostname_class
['isp', 'ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
72.192.0.0 - 72.223.255.255
last_activity
2025-12-08 12:26:26
last_warden_event
2025-12-08 12:26:26
rep
0.023809523809523805
reserved_range
0
Shodan's InternetDB
Open ports: 1723
Tags: vpn
CPEs:
ts_added
2025-10-29 15:45:15.739000
ts_last_update
2025-12-16 15:45:20.048000

Warden event timeline

DShield event timeline

Presence on blacklists