URL / Domain Profile

🌐 https://sslbl.abuse.ch/blacklist/

URL · host sslbl.abuse.ch · threat 0.50 (HIGH) · IP Blocklists
First seen 2026-08-06 13:07:47 · last seen 2026-08-23 06:21:01

Threat score

0.50
MEDIUM

Sightings

8
5 sources

Subdomains (local)

0
from indicators

Related IPs

5
A/AAAA records

DNS records (local)

2
2 types

Reporting sources

5
1 enrichments

📡 Reporting-source breakdown

C2 Attribution
2
C2 Certificates
2
IP Blocklists
1
5 total source links on this indicator.

🏷 Tag breakdown (domain family)

url
1
auto-tagged
1
medium-severity
1

📈 DNS record-type counts

A
1
CNAME
1

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for sslbl.abuse.ch. Resolve & cache.

🏷 Tags

url medium-severity auto-tagged
CategoryIP Blocklists
SeverityMEDIUM

📡 DNS Records

Stored (local dns_records) — 2

TypeValueTTLChecked
A 146.75.94.49 60 2026-08-20
CNAME p2.shared.global.fastly.net 60 2026-08-20

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A p2.shared.global.fastly.net. 60
A 151.101.2.49 60
A 151.101.130.49 60
A 151.101.194.49 60
A 151.101.66.49 60
AAAA p2.shared.global.fastly.net. 60
MX p2.shared.global.fastly.net. 59
NS p2.shared.global.fastly.net. 60
TXT p2.shared.global.fastly.net. 60
CNAME p2.shared.global.fastly.net. 54

🖥 Related IPs (5)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

146.75.94.49 151.101.2.49 151.101.130.49 151.101.194.49 151.101.66.49

🌐 Subdomains — local intel (0)

No subdomains of sslbl.abuse.ch in local intel. Check crt.sh ↗

📡 Reporting Sources (5)

SSLBL IPsIP Blocklists
SSL Blacklist (family)C2 Certificates
SSLBL Botnet C2 IPsC2 Attribution
SSLBL Botnet C2C2 Attribution
SSLBL JA3C2 Certificates

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

🧩 Enrichment Data (1 records)

classification 2d ago
{
    "ioc_type": "url",
    "category": "IP Blocklists",
    "threat_score": 0.5
}

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools