Is 50.225.176.238 malicious?
IP reputation report for 50.225.176.238: blocklist detections, geolocation, ASN, WHOIS and security posture, aggregated from 100+ threat intelligence sources.
50.225.176.238 is listed on 51 threat intelligence sources
Detected by 51 threat intelligence sources in the isMalicious dataset — review before trusting this IP.
Threat verdict
VerdictListed on blocklists
Appears on threat intelligence blocklists — treat with caution.
Blocklist detections51 sources
Categoriesattack, abuse, malware, phishing, suspicious, bruteforce, malicious, attacks, botnet, c2
Confidence score100/100
Aggregated confidence across the sources reporting this indicator.
Last updated2026-07-09
Network & location
LocationDerry, New Hampshire, United States
ISPComcast Cable Communications, LLC
ASNAS7922 — Comcast Cable Communications, LLC
Network50.128.0.0/9
CompanyComcast Cable Communications, LLC
InfrastructureProxy
Security posture
Open ports22, 3306, 5432, 8080, 18081, 28015
Detections
- Duggytuxy - Blacklist Ips For Fortinet Firewall Aa.txt
- FireHOL - Blocklist Deattack
- FireHOL - Blocklist De Sshattack
- FireHOL - Blocklist De Strongipsattack
- FireHOL - Blocklist Net Uaabuse
- FireHOL - Darklist Deattack
- FireHOL - Firehol Level2attack
- FireHOL - Firehol Level4attack
- FireHOL - Greensnowattack
- Scriptzteam - BlockList V4 Ips.txtmalware
- Opendbl Net - Blocklistde All.listmalware
- Opendbl Net - Ipsum.listmalware
- Romain Marcoux - Malicious Outgoing IPsphishing
- Romain Marcoux - Malicious IPsphishing
- Blocklist - All SSH attacks (48h)attack
- Blocklist - All Attacks (48h)attack
- Blocklist - All StrongIPs attacks (2 month + 5k attacks)attack
- Greensnow - Attacks Multi-protocolsphishing
- CyberCure Blocked URL Feedmalware
- CyberCure Hash Feedmalware
- CyberCure IP Feedmalware
- IPsum Level 2suspicious
- IPsum Level 3suspicious
- SSH Password Authbruteforce
+27 more sources in the full report.