IP address


--85.208.84.142
Shodan(more info)
Passive DNS
Tags:
IP blacklists
UCEPROTECT L1
85.208.84.142 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-09-12 23:45:00.686000
Was present on blacklist at: 2025-08-19 15:45, 2025-08-19 23:45, 2025-08-20 07:45, 2025-08-20 15:45, 2025-08-20 23:45, 2025-08-21 07:45, 2025-08-21 15:45, 2025-08-21 23:45, 2025-08-22 07:45, 2025-08-22 15:45, 2025-08-22 23:45, 2025-08-23 07:45, 2025-08-23 15:45, 2025-08-23 23:45, 2025-08-24 07:45, 2025-08-24 15:45, 2025-08-24 23:45, 2025-08-25 07:45, 2025-08-25 15:45, 2025-08-25 23:45, 2025-08-26 07:45, 2025-08-26 15:45, 2025-08-26 23:45, 2025-08-27 07:45, 2025-08-27 15:45, 2025-08-27 23:45, 2025-08-28 07:45, 2025-08-28 15:45, 2025-08-28 23:45, 2025-08-29 07:45, 2025-08-29 15:45, 2025-08-29 23:45, 2025-08-30 07:45, 2025-08-30 15:45, 2025-08-30 23:45, 2025-08-31 07:45, 2025-08-31 15:45, 2025-08-31 23:45, 2025-09-01 07:45, 2025-09-01 15:45, 2025-09-01 23:45, 2025-09-02 07:45, 2025-09-02 15:45, 2025-09-02 23:45, 2025-09-03 07:45, 2025-09-03 15:45, 2025-09-03 23:45, 2025-09-04 07:45, 2025-09-04 15:45, 2025-09-04 23:45, 2025-09-05 07:45, 2025-09-05 15:45, 2025-09-05 23:45, 2025-09-06 07:45, 2025-09-06 15:45, 2025-09-06 23:45, 2025-09-07 07:45, 2025-09-07 15:45, 2025-09-07 23:45, 2025-09-08 07:45, 2025-09-08 15:45, 2025-09-08 23:45, 2025-09-09 07:45, 2025-09-09 15:45, 2025-09-09 23:45, 2025-09-10 07:45, 2025-09-10 15:45, 2025-09-12 15:45, 2025-09-12 23:45
DShield reports (IP summary, reports)
2025-08-27
Number of reports: 29
Distinct targets: 13
OTX pulses
[68a8626ba9aa56cebc11b3ec] 2025-08-22 12:28:27.227000 | RDP honeypot logs for 2025/08/22
Author name:jnazario
Pulse modified:2025-08-22 12:28:27.227000
Indicator created:2025-08-22 12:28:28
Indicator role:None
Indicator title:
Indicator expiration:2025-09-21 12:00:00
[68ac56a3a08c0f3c2c5b7133] 2025-08-25 12:27:15.351000 | RDP honeypot logs for 2025/08/25
Author name:jnazario
Pulse modified:2025-08-25 12:27:15.351000
Indicator created:2025-08-25 12:27:16
Indicator role:None
Indicator title:
Indicator expiration:2025-09-24 12:00:00
[68b985d5a75472c80c9f6518] 2025-09-04 12:28:05.522000 | RDP honeypot logs for 2025/09/04
Author name:jnazario
Pulse modified:2025-09-04 12:28:05.522000
Indicator created:2025-09-04 12:28:07
Indicator role:None
Indicator title:
Indicator expiration:2025-10-04 12:00:00
Origin AS
AS209309 - ONIKS-AS
AS211659 - STIMUL-AS
BGP Prefix
85.208.84.0/24
geo
Russia, Moscow
🕑 Europe/Moscow
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
85.208.84.0 - 85.208.84.255
last_activity
2025-09-04 16:01:23.862000
reserved_range
0
Shodan's InternetDB
Open ports: 137, 445, 3389
Tags: self-signed, eol-os
CPEs:
ts_added
2025-08-19 16:02:33.184000
ts_last_update
2025-09-13 00:00:04.583000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses