ITMD logo

IP Intelligence Lookup

View geolocation, threat activity, WHOIS, blacklist status, and supporting network context in one report.

8.8.8.8

Report created 2026-05-26 15:50:41 UTC

0
/ 100
Clean
No threat indicators found.
How is this score calculated?
119 threat feeds checked 5,214,886 total feed entries

AI Threat Assessment

The IP address 8.8.8.8 is a Clean asset owned by Google LLC (AS15169) and is globally recognized as Google's public DNS resolver. The risk score is 0 because it shows no indicators of compromise across 90 threat intelligence feeds, with no malicious, proxy, VPN, or TOR activity reported. The open ports (53/DNS and 443/HTTPS) are expected for this essential public service. Recommended action: no action; this IP is a legitimate infrastructure component and should not be blocked, as doing so would disrupt DNS resolution for users.

Location & Network

Where this IP address is physically located and which internet provider or organisation owns it. The map pin shows the approximate location IP geolocation is accurate to the city level at best.

CountryUnited States (US)
World RegionAmericas Northern America
RegionN/A
CityN/A
ASNAS15169
OrganizationGoogle LLC
TimezoneAmerica/Chicago
Lat / Lon37.751, -97.822
Reverse DNSdns.google

WHOIS

The official registration record for the IP address block. It shows who was allocated this range of IPs, how to contact their abuse team, and when the record was last updated.

CIDR Block8.8.8.0/24
IP Range8.8.8.0 8.8.8.255
Net NameGOGL
OrganisationGOOGLE - Google LLC, US
CountryUnited States  Americas Northern America
Created2023-12-28
Updated2023-12-28
Abuse Emailnetwork-abuse@google.com
Statusactive

Threat Flags

Whether this IP appears in known Tor, proxy, or VPN databases. Click a True badge to see exactly which feeds flagged it.

MaliciousFalse
Tor ExitFalse
ProxyFalse
VPN / AnonymousFalse

TLS Certificate

The security certificate this server presents when you connect over HTTPS. It proves the server's identity and enables encrypted communication. Click any row label to read a plain-English explanation of that field.

Common Namedns.google
IssuerWR2 / Google Trust Services / US
Valid From2026-05-07 15:54:00 UTC
Valid Until2026-07-30 15:53:59 UTC (64d left)
TLS VersionTLSv1.3
CipherTLS_AES_256_GCM_SHA384 (256-bit)
Serial117271883940293663130581390138217699186
SHA-256D0:7B:43:FD:8D:3D:7A:AC:B9:57:50:66:74:17:CC:81:26:4B:60:08:9C:72:DF:1A:7B:0A:18:62:DC:79:1D:96
DNS SANsdns.google, dns.google.com, *.dns.google.com, 8888.google, dns64.dns.google
IP SANs8.8.8.8, 8.8.4.4, 8.8.8.53, 2001:4860:4860::8888, 2001:4860:4860::8844, 2001:4860:4860::6464, 2001:4860:4860::64
OCSPhttp://o.pki.goog/wr2
CRLhttp://c.pki.goog/wr2/GSyT1N4PBrg.crl

Honeypot Activity

Whether this IP has been seen attacking honeypots decoy systems set up to attract and log malicious traffic. Hits here are a strong indicator of scanning or attack activity.

Count0
FoundFalse
Ip8.8.8.8
Time Range48h

Open Ports

Ports that are actively accepting connections on this IP right now. Each open port corresponds to a service or application. Unexpected open ports can indicate misconfiguration or malicious software.

PortServiceBanner
53DNS
443HTTPS

Traceroute

The network path packets travel from this server to the target IP, hop by hop. Each row is a router along the way. The map shows the geographic path the traffic takes across the internet.

#AddressCountryASN / OrgTypeRTT
108.8.8.8 destUnited StatesAS15169 Google LLCPublic

Blacklist & Feed Checks

This IP was checked against hundreds of threat intelligence feeds and DNS blacklists maintained by security organisations worldwide. A Listed result means the IP appears in that feed, which may indicate malicious activity, spam, or abuse. Not every listing means active danger some feeds are conservative and flag IPs for minor or historical reasons.

URL Feed Checks

FeedURLEntriesStatus
EmergingThreatshttp://rules.emergingthreats.net/blockrules/compromised-ips.txt
IPs known to host malware, botnets, or other malicious content, compiled by the Proofpoint Emerging Threats research team.
516Not Listed
AlienVaulthttp://reputation.alienvault.com/reputation.data
Community-driven feed aggregating IPs reported for malicious activity from security researchers worldwide.
609Not Listed
BlocklistDEhttp://www.blocklist.de/lists/bruteforcelogin.txt
IPs caught brute-forcing login pages, auto-reported by servers running the blocklist.de honeypot agent.
647Not Listed
Feodohttp://rules.emergingthreats.net/blockrules/compromised-ips.txt
IPs associated with Feodo/Emotet banking trojan infrastructure.
516Not Listed
Abuse.ch Feodo Trackerhttps://feodotracker.abuse.ch/downloads/ipblocklist.txt
Command-and-control servers for the Feodo/Emotet banking trojan family, tracked by abuse.ch.
5Not Listed
Abuse.ch SSLBLhttps://sslbl.abuse.ch/blacklist/sslipblacklist.txt
IPs communicating with malware over SSL, identified by abuse.ch via SSL certificate fingerprints.
0Not Listed
CINS Armyhttps://cinsscore.com/list/ci-badguys.txt
IPs scoring poorly on the CINS (Collective Intelligence Network Security) reputation system based on internet background noise.
15000Not Listed
Spamhaus DROPhttps://www.spamhaus.org/drop/drop.txt
Netblocks Spamhaus recommends blocking entirely hijacked or leased IP space used exclusively for criminal activity.
1610Not Listed
Spamhaus EDROPhttps://www.spamhaus.org/drop/edrop.txt
Extended DROP: suballocated netblocks controlled by spam gangs or criminal organisations not yet in DROP.
0Not Listed
FireHOL Level 1https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset
The strictest FireHOL blocklist IPs that are almost certainly hostile with very few false positives. Suitable for all networks.
4452Not Listed
Emerging Threats botcchttps://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
Known botnet command-and-control IPs actively instructing malware, from Emerging Threats rule sets.
1651Not Listed
Greensnowhttps://blocklist.greensnow.co/greensnow.txt
IPs attacking SSH servers, reported by a globally distributed network of honeypots run by greensnow.co.
5982Not Listed
FireHOL Level 2https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level2.netset
A broader known-bad IP set aggregated from multiple reputable threat intelligence feeds.
17849Not Listed
FireHOL Level 3https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level3.netset
Extended threat coverage including lower-confidence but still significant threat sources.
13654Not Listed
FireHOL Level 4https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level4.netset
Widest FireHOL coverage; includes IPs flagged across numerous historical and current threat datasets.
81359Not Listed
FireHOL Abusers 1dhttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_abusers_1d.netset
IPs that performed abusive scanning or attack activity within the last 24 hours.
4087Not Listed
FireHOL Abusers 30dhttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_abusers_30d.netset
IPs with confirmed abusive behaviour in the past 30 days.
136663Not Listed
FireHOL Anonymoushttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_anonymous.netset
Aggregated Tor exit nodes, VPNs, and open proxies sources used to mask the true origin of traffic.
2246409Not Listed
FireHOL Webclienthttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_webclient.netset
IPs known to originate malicious web-based attacks including drive-by exploits and web scraping campaigns.
334Not Listed
Tor Exit Nodeshttps://check.torproject.org/torbulkexitlist
Official Tor Project list of active exit nodes IPs that relay anonymous Tor traffic onto the public internet.
1278Not Listed
Tor Exit Nodes Fallbackhttps://check.torproject.org/cgi-bin/TorBulkExitList.py
Official Tor Project bulk exit list script endpoint used as a fallback source when the primary Tor feed is unavailable.
1278Not Listed
Blocklist.de SSHhttp://www.blocklist.de/lists/ssh.txt
IPs that have attempted brute-force attacks against SSH servers, reported via blocklist.de.
4890Not Listed
Blocklist.de SMTPhttp://www.blocklist.de/lists/mail.txt
IPs caught sending spam or attacking mail servers, reported via blocklist.de.
13572Not Listed
IPsumhttps://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt
Aggregated threat intelligence scoring IPs by how many independent blacklists they appear on higher scores mean more sources agree.
122699Not Listed
Abuse.ch Feodo Tracker Aggressivehttps://feodotracker.abuse.ch/downloads/ipblocklist_aggressive.txt
Strict version of Feodo Tracker including suspected as well as confirmed C2 hosts.
7607Not Listed
Team Cymru Full Bogonshttps://www.team-cymru.org/Services/Bogons/fullbogons-ipv4.txt
IP ranges that should never appear on the public internet unallocated, reserved, or private address space.
2939Not Listed
Blocklist.de Allhttp://www.blocklist.de/lists/all.txt
Combined blocklist.de feed covering all attack types reported across all of their sensors.
23849Not Listed
Blocklist.de Apachehttp://www.blocklist.de/lists/apache.txt
IPs attacking Apache web servers with exploits or brute-force attempts.
8760Not Listed
Blocklist.de Botshttp://www.blocklist.de/lists/bots.txt
Automated bot IPs scraping, scanning, or attacking web services.
2680Not Listed
Blocklist.de SIPhttp://www.blocklist.de/lists/sip.txt
IPs attempting to abuse or brute-force SIP/VoIP telephone systems.
40Not Listed
Blocklist.de StrongIPshttp://www.blocklist.de/lists/strongips.txt
IPs with repeated, severe violations across multiple blocklist.de categories.
292Not Listed
Binary Defensehttps://www.binarydefense.com/banlist.txt
IPs observed performing internet-wide attacks, maintained by Binary Defense Systems' artillery honeypot project.
1206Not Listed
StopForumSpam Toxichttps://www.stopforumspam.com/downloads/toxic_ip_cidr.txt
CIDR ranges that are prolific sources of spam forum registrations and automated abuse.
56Not Listed
VoIPBLhttp://www.voipbl.org/update/
IPs targeting VoIP infrastructure with toll fraud, SIP scanning, and brute-force attacks.
90545Not Listed
DShield 1dhttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/dshield_1d.netset
Top attacking IPs from the last 24 hours compiled by the SANS Internet Storm Center from global firewall logs.
28Not Listed
Etnetera Aggressivehttps://security.etnetera.cz/feeds/etn_aggressive.txt
IPs performing active attacks on infrastructure, maintained by the Czech security firm Etnetera.
452Not Listed
Blocklist.de Postfixhttp://www.blocklist.de/lists/postfix.txt
IPs attacking Postfix mail servers, reported via blocklist.de.
13572Not Listed
Mirai Trackerhttps://mirai.security.gives/data/ip_list.txt
IPs actively running or previously running the Mirai IoT botnet, tracked by security researchers.
0Not Listed
FireHOL Proxieshttps://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_proxies.netset
Open and anonymous proxies aggregated from multiple sources, used to relay or anonymise traffic.
2240581Not Listed
Total indicators checked across source URLs: 5067667

DNSBL Results

DNS Blacklists work differently from the URL feeds above. Instead of downloading a file of bad IPs, your system does a live DNS query the same technology used to look up website addresses and asks the blacklist operator in real-time whether this IP is listed. It is faster and always up to date, but it only returns a yes or no with no entry count. The feeds above are bulk lists you download and search locally; DNSBLs are live lookups against someone else's database.

Not listed on any of the 49 checked DNSBLs
DNSBLStatusDetails
b.barracudacentral.orgNot Listed
bl.spamcop.netNot Listed
blacklist.woody.chNot Listed
cbl.abuseat.orgNot Listed
combined.abuse.chNot Listed
combined.rbl.msrbl.netNot Listed
dnsbl.cyberlogic.netNot Listed
dnsbl.sorbs.netNot Listed
drone.abuse.chNot Listed
drone.abuse.chNot Listed
dul.dnsbl.sorbs.netNot Listed
dul.ruNot Listed
dynip.rothen.comNot Listed
http.dnsbl.sorbs.netNot Listed
images.rbl.msrbl.netNot Listed
ips.backscatterer.orgNot Listed
korea.services.netNot Listed
misc.dnsbl.sorbs.netNot Listed
ohps.dnsbl.net.auNot Listed
omrs.dnsbl.net.auNot Listed
osps.dnsbl.net.auNot Listed
osrs.dnsbl.net.auNot Listed
owfs.dnsbl.net.auNot Listed
pbl.spamhaus.orgNot Listed
phishing.rbl.msrbl.netNot Listed
probes.dnsbl.net.auNot Listed
proxy.bl.gweep.caNot Listed
rbl.interserver.netNot Listed
rdts.dnsbl.net.auNot Listed
relays.bl.gweep.caNot Listed
relays.nether.netNot Listed
residential.block.transip.nlNot Listed
ricn.dnsbl.net.auNot Listed
smtp.dnsbl.sorbs.netNot Listed
socks.dnsbl.sorbs.netNot Listed
spam.abuse.chNot Listed
spam.dnsbl.sorbs.netNot Listed
spam.rbl.msrbl.netNot Listed
spamrbl.imp.chNot Listed
t3direct.dnsbl.net.auNot Listed
ubl.lashback.comNot Listed
ubl.unsubscore.comNot Listed
virus.rbl.jpNot Listed
virus.rbl.msrbl.netNot Listed
web.dnsbl.sorbs.netNot Listed
wormrbl.imp.chNot Listed
xbl.spamhaus.orgNot Listed
zen.spamhaus.orgNot Listed
zombie.dnsbl.sorbs.netNot Listed

Recent Jobs

Review queued, running, completed, or failed jobs and jump to their status or final result.

EndpointTargetFormatStatusCreatedAction
ip8.8.8.8htmlrunning2026-05-26 15:50:38Check Status
ip47.84.196.31jsondone2026-05-26 14:15:00Open Result
ip47.84.196.31htmldone2026-05-26 14:14:49Open Result
ip118.193.33.130jsondone2026-05-26 14:10:49Open Result
ip118.193.33.130htmldone2026-05-26 14:10:38Open Result
ip165.154.173.226jsondone2026-05-25 15:54:32Open Result
ip165.154.173.226htmldone2026-05-25 15:54:22Open Result
ip167.99.85.130jsondone2026-05-25 15:47:52Open Result
ip167.99.85.130htmldone2026-05-25 15:47:36Open Result
ip8.8.8.8jsondone2026-05-25 14:27:30Open Result
ip8.8.8.8htmldone2026-05-25 14:27:20Open Result
ip160.153.0.6jsondone2026-05-24 15:48:53Open Result
ip160.153.0.6jsondone2026-05-24 15:48:51Open Result
ip160.153.0.6htmldone2026-05-24 15:48:44Open Result
ip160.153.0.6htmldone2026-05-24 15:48:42Open Result
ip160.153.0.6htmlerror
can't start new thread
2026-05-24 15:48:04Check Status
ip160.153.0.6htmlerror
can't start new thread
2026-05-24 15:48:03Check Status
ip160.153.0.6jsondone2026-05-24 02:53:08Open Result
ip160.153.0.6jsondone2026-05-24 02:53:04Open Result
ip160.153.0.6htmldone2026-05-24 02:52:58Open Result