IP address


--85.137.48.186
Shodan(more info)
Passive DNS
Tags:
IP blacklists
UCEPROTECT L1
85.137.48.186 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-04-06 15:45:01.104000
Was present on blacklist at: 2026-03-26 00:45, 2026-03-26 08:45, 2026-03-26 16:45, 2026-03-27 00:45, 2026-03-27 08:45, 2026-03-27 16:45, 2026-03-28 00:45, 2026-03-28 08:45, 2026-03-28 16:45, 2026-03-29 00:45, 2026-03-29 07:45, 2026-03-29 15:45, 2026-03-29 23:45, 2026-03-30 07:45, 2026-03-30 15:45, 2026-03-30 23:45, 2026-03-31 07:45, 2026-03-31 15:45, 2026-03-31 23:45, 2026-04-01 07:45, 2026-04-01 15:45, 2026-04-01 23:45, 2026-04-02 07:45, 2026-04-02 15:45, 2026-04-02 23:45, 2026-04-03 07:45, 2026-04-03 15:45, 2026-04-03 23:45, 2026-04-04 07:45, 2026-04-04 15:45, 2026-04-04 23:45, 2026-04-05 07:45, 2026-04-05 15:45, 2026-04-05 23:45, 2026-04-06 07:45, 2026-04-06 15:45
Spamhaus SBL CSS
85.137.48.186 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-04-02 01:05:34.844000
Was present on blacklist at: 2026-03-26 01:05, 2026-04-02 01:05

Threat categories

TLRoleCategoryDetails
43 src

Origin AS
AS43641 - Sollutium-NL
BGP Prefix
85.137.48.0/24
geo
Netherlands, Haarlem
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
85.136.0.0 - 85.137.255.255
reserved_range
0
Shodan's InternetDB
Open ports: 21, 25, 80, 443, 993, 8888
Tags: starttls, self-signed
CPEs: cpe:/a:f5:nginx, cpe:/a:f5:nginx:1.28.0, cpe:/a:exim:exim:4.93
ts_added
2026-03-26 01:05:24.137000
ts_last_update
2026-04-06 16:28:46.975000

Warden event timeline

DShield event timeline

Presence on blacklists