Threat LevelHIGH53/1001 rule type
1 incident on record · confirmed on global blocklist · last seen 24d ago · bulletproof hosting
| PTR | N/A |
| Org / ASN | Feo Prest SRL |
| Country | 🇮🇷 Iran |
| City | Tehran, Tehran |
| Timezone | Asia/Tehran |
Iranian Attack InfrastructureFEO PREST SRL (Iran)
This IP originates from an Iranian netblock (FEO PREST SRL range) that is among the most heavily reported attack infrastructure in global threat databases, with adjacent IPs accumulating over 326,000 independent abuse reports and 100% abuse confidence ratings. The scale and duration of abuse is consistent with state-adjacent or professionally-operated Iranian offensive infrastructure targeting servers globally.
Attack Analysis
Listed on 2 threat-intelligence blocklists
- Spamhaus DROP — Spamhaus DROP lists netblocks hijacked or leased by professional spam and cybercrime operations. Very low false-positive rate: no legitimate traffic is expected from these ranges.
- FireHOL level1 — FireHOL level1 merges DShield, Spamhaus DROP, bogon ranges and Feodo botnet servers into one curated list built for very low false positives. When DShield or Spamhaus DROP also match, this one adds no independent evidence, since it already contains them.
Reports (1)
| Date | Severity | Description |
|---|---|---|
| 6 Sep 2026 - 00:58 | low | Spamhaus DROP (hijacked/spammer netblocks), FireHOL level1 (DShield+Spamhaus DROP+bogons+Feodo, merged, low-FP) |
EagleEye Intelligence