Transparency

BIND is the source of truth for live listings • meta.json records observation and delisting history

Transparency snapshot

Back to DNSBL
Active listings
2,649
Live from BIND zone (A + AAAA)
Threat activity (7 days)
13
Unique suspicious public IPs • 706 matched events • 1,698 requests evaluated
Repeat offenders
120
Threatmail: 71 • Apache security: 49
Lifecycle
Active
Pending review: 0 • Expiring ≤7d: 31 • Expired last run: 2
Delisted records
4
1 in the last 7 days • unique IPs with a recorded delist
Mail feeds
Active
Threatmail: active
User reports: not enabled • last 2026-06-25 06:35 BST
History coverage
70.1%
1,858 of 2,649 live listings have metadata
Last zone update
2026-06-25 06:17 BST
Authoritative BIND zone last modified
Live status, return code and TXT reason are reconciled directly against the BIND zone. An address is marked DELISTED only when a real delist timestamp, counter or audit event exists; otherwise a non-live historical address is OBSERVED. Repeat-offender totals are grouped by the latest sanitised attack source; complete event history is available only through the per-IP JSON feed and delist information. Apache activity cache updated 2026-06-25 06:35 BST.
BIND records: IPv4 A = 2,649 • IPv6 AAAA = 0 • TXT = 2,649 • SOA serial 2026062508.

Listings history

Live BIND entries plus observation and delisting history. Times use UK local GMT/BST.

Clear

Showing 1,701–1,800 of 2,649 matching records.

IP Status Code Reason Last activity Sources Lists / Delists Details
64.227.82.174 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2 threatmail 3 / 0
172.64.244.69 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 2 / 0
118.148.168.74 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 3 / 0
160.119.76.24 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 213 threatmail 2 / 0
89.42.218.114 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 10 / 0
31.11.36.5 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 8 / 0
183.90.187.210 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 221 / 0
66.132.186.177 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 web:post 3 / 0
217.21.90.112 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 19 / 0
70.153.161.0 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 42 / 0
176.67.58.47 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 3 / 0
46.43.65.3 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 9 / 0
84.242.53.32 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
176.119.251.25 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
20.113.29.118 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 574 / 0
24.22.88.55 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 4 / 0
38.6.37.154 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 69 / 0
150.228.187.129 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 3 / 0
117.55.228.142 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
110.137.34.157 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
114.10.41.136 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
157.85.209.118 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
153.117.33.35 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
180.190.241.9 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
103.188.169.147 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
181.228.242.123 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 6 / 0
138.84.114.53 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
202.51.197.33 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
74.244.85.38 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
180.180.114.125 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
45.228.188.196 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 5 / 0
147.236.122.237 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
186.19.22.241 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET SCAN JAWS Webserver Unauthenticated Shell Command Execution threatmail 6 / 0
212.58.102.249 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
51.36.243.155 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 6 / 0
112.203.136.117 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
190.148.49.156 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
183.182.111.13 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
103.195.236.35 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 6 / 0
213.254.134.82 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
102.204.4.4 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
154.125.245.102 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
200.225.119.241 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
202.187.230.179 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 6 / 0
81.230.60.253 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 6 / 0
20.171.125.215 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
68.167.181.179 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 6 / 0
190.30.208.251 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET SCAN JAWS Webserver Unauthenticated Shell Command Execution threatmail 6 / 0
124.104.188.146 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
190.61.40.218 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
38.41.19.65 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
129.224.215.91 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
216.234.223.227 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
212.14.250.141 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
68.154.115.184 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
20.171.51.211 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
20.169.75.197 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
57.151.128.241 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
52.188.87.6 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
52.161.50.35 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / GPL WEB_SERVER .htpasswd access threatmail 6 / 0
34.238.127.113 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) threatmail 6 / 0
136.32.228.192 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) threatmail 6 / 0
188.161.88.80 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
68.65.121.100 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) threatmail 6 / 0
195.242.178.167 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 6 / 0
116.99.49.208 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 5 / 0
45.130.127.36 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 5 / 0
89.58.31.64 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 4 / 0
178.162.196.48 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 3 / 0
75.50.118.227 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 22 / 0
9.234.8.54 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 14 threatmail 2 / 0
143.42.1.34 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 185 threatmail 2 / 0
45.198.224.144 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 63 threatmail 2 / 0
65.49.1.160 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
45.119.98.180 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 110 / 0
20.80.105.83 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 34 threatmail 2 / 0
217.160.0.222 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 95 / 0
216.180.246.58 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 289 threatmail 2 / 0
205.210.31.251 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
52.165.89.126 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 98 threatmail 2 / 0
103.140.158.3 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 143 threatmail 2 / 0
195.230.103.249 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 278 threatmail 2 / 0
20.64.106.77 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 30 threatmail 2 / 0
193.163.125.181 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
64.62.197.107 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
167.94.146.48 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 231 threatmail 2 / 0
64.62.197.115 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
194.88.98.117 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 273 threatmail 2 / 0
66.132.195.106 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
147.185.132.126 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
205.210.31.176 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
167.94.146.51 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 231 threatmail 2 / 0
20.65.144.62 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 31 threatmail 1 / 0
66.132.195.100 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
54.197.33.93 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 101 threatmail 1 / 0
54.145.62.252 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 100 threatmail 1 / 0
52.188.231.42 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 99 threatmail 3 / 0
20.64.105.145 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 30 threatmail 3 / 0
66.132.172.216 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 3 / 0
178.105.163.37 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 6 / 0

Lists / Delists shows list_count and delist_count. OBSERVED means the IP exists in history but is not currently in BIND and has no recorded delist event. Trusted addresses in /etc/scotnet/dnsbl-public-hide.txt are omitted from this public history table.