IP address


.55694.26.88.5959.88.26.94.tbc.bg
Shodan(more info)
Passive DNS
Tags: IP in hostname Scanner
IP blacklists
AbuseIPDB
94.26.88.59 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-12-18 05:00:00.690000
Was present on blacklist at: 2025-11-04 05:00, 2025-11-05 05:00, 2025-11-10 05:00, 2025-11-11 05:00, 2025-11-12 05:00, 2025-11-13 05:00, 2025-11-14 05:00, 2025-11-15 05:00, 2025-11-16 05:00, 2025-11-17 05:00, 2025-11-18 05:00, 2025-11-19 05:00, 2025-11-20 05:00, 2025-11-21 05:00, 2025-11-22 05:00, 2025-11-23 05:00, 2025-12-04 05:00, 2025-12-05 05:00, 2025-12-06 05:00, 2025-12-07 05:00, 2025-12-08 05:00, 2025-12-09 05:00, 2025-12-10 05:00, 2025-12-11 05:00, 2025-12-13 05:00, 2025-12-14 05:00, 2025-12-15 05:00, 2025-12-16 05:00, 2025-12-17 05:00, 2025-12-18 05:00
Spamhaus SBL
94.26.88.59 is listed on the Spamhaus SBL blacklist.

Description: The Spamhaus Block List ("SBL") Advisory is a database of IP addresses from which Spamhaus does not recommend the acceptance of electronic mail.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-16 05:17:23.257000
Was present on blacklist at: 2025-11-04 05:01, 2025-11-11 05:01, 2025-11-18 05:01, 2025-11-25 05:01, 2025-12-02 05:01, 2025-12-09 05:01, 2025-12-16 05:17
Spamhaus DROP
94.26.88.59 is listed on the Spamhaus DROP blacklist.

Description: Spamhaus DROP (Don't Route Or Peer) list. Netblocks controlled by spammers or cyber criminals. The DROP lists are a tiny subset of the SBL, designed for use by firewalls and routing equipment to filter out the malicious traffic from these netblocks.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-16 05:17:23.257000
Was present on blacklist at: 2025-11-04 05:01, 2025-11-11 05:01, 2025-11-18 05:01, 2025-11-25 05:01, 2025-12-02 05:01, 2025-12-09 05:01, 2025-12-16 05:17
Turris greylist
94.26.88.59 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-18 22:15:00.167000
Was present on blacklist at: 2025-11-05 22:15, 2025-11-11 22:15, 2025-11-12 22:15, 2025-11-13 22:15, 2025-11-15 22:15, 2025-11-16 22:15, 2025-11-17 22:15, 2025-11-18 22:15, 2025-11-20 22:15, 2025-11-21 22:15, 2025-11-22 22:15, 2025-11-24 22:15, 2025-12-05 22:15, 2025-12-06 22:15, 2025-12-07 22:15, 2025-12-08 22:15, 2025-12-09 22:15, 2025-12-11 22:15, 2025-12-12 22:15, 2025-12-15 22:15, 2025-12-16 22:15, 2025-12-17 22:15, 2025-12-18 22:15
Warden events (2996)
2025-12-18
ReconScanning (node.368407): 16
ReconScanning (node.4dc198): 16
2025-12-17
ReconScanning (node.4dc198): 288
ReconScanning (node.368407): 286
2025-12-16
ReconScanning (node.368407): 284
ReconScanning (node.4dc198): 288
2025-12-15
ReconScanning (node.4dc198): 287
ReconScanning (node.368407): 275
2025-12-14
ReconScanning (node.4dc198): 286
ReconScanning (node.368407): 285
2025-12-13
ReconScanning (node.4dc198): 287
ReconScanning (node.368407): 272
2025-12-12
ReconScanning (node.368407): 40
ReconScanning (node.4dc198): 40
2025-12-10
ReconScanning (node.4dc198): 4
2025-12-09
ReconScanning (node.4dc198): 29
2025-12-08
ReconScanning (node.4dc198): 13
DShield reports (IP summary, reports)
2025-11-03
Number of reports: 8158
Distinct targets: 6408
2025-11-04
Number of reports: 8158
Distinct targets: 6408
2025-11-09
Number of reports: 7466
Distinct targets: 5946
2025-11-10
Number of reports: 14585
Distinct targets: 11610
2025-11-11
Number of reports: 14585
Distinct targets: 11610
2025-11-12
Number of reports: 13992
Distinct targets: 11053
2025-11-13
Number of reports: 15795
Distinct targets: 12958
2025-11-14
Number of reports: 14419
Distinct targets: 12809
2025-11-15
Number of reports: 13548
Distinct targets: 9710
2025-11-16
Number of reports: 13548
Distinct targets: 9710
2025-11-17
Number of reports: 16739
Distinct targets: 14028
2025-11-18
Number of reports: 16739
Distinct targets: 14028
2025-11-19
Number of reports: 13760
Distinct targets: 12671
2025-11-20
Number of reports: 13760
Distinct targets: 12671
2025-11-21
Number of reports: 17484
Distinct targets: 14054
2025-11-22
Number of reports: 17741
Distinct targets: 13647
2025-11-23
Number of reports: 7234
Distinct targets: 5421
2025-12-03
Number of reports: 158
Distinct targets: 118
2025-12-04
Number of reports: 16166
Distinct targets: 13623
2025-12-05
Number of reports: 10501
Distinct targets: 10491
2025-12-06
Number of reports: 5873
Distinct targets: 5870
2025-12-07
Number of reports: 5873
Distinct targets: 5870
2025-12-08
Number of reports: 14644
Distinct targets: 12634
2025-12-09
Number of reports: 16393
Distinct targets: 12955
2025-12-10
Number of reports: 13400
Distinct targets: 11205
2025-12-11
Number of reports: 5528
Distinct targets: 4517
2025-12-12
Number of reports: 5528
Distinct targets: 4517
2025-12-13
Number of reports: 4087
Distinct targets: 3171
2025-12-14
Number of reports: 4052
Distinct targets: 3240
2025-12-15
Number of reports: 1898
Distinct targets: 1689
2025-12-16
Number of reports: 1534
Distinct targets: 1366
2025-12-17
Number of reports: 4494
Distinct targets: 3669
2025-12-18
Number of reports: 4494
Distinct targets: 3669
Origin AS
AS201814 - PL-SKYTECH-AS
BGP Prefix
94.26.88.0/24
geo
Bulgaria
🕑 Europe/Sofia
hostname
59.88.26.94.tbc.bg
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
94.26.88.0 - 94.26.88.255
last_activity
2025-12-18 01:14:57
last_warden_event
2025-12-18 01:14:57
rep
0.5556530180431547
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags: scanner
CPEs: cpe:/o:linux:linux_kernel, cpe:/o:debian:debian_linux, cpe:/a:openbsd:openssh:7.9p1
ts_added
2025-11-04 05:01:03.857000
ts_last_update
2025-12-19 05:02:16.557000

Warden event timeline

DShield event timeline

Presence on blacklists