IP address


.321116.140.208.227
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
116.140.208.227 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2024-05-18 02:50:01.025000
Was present on blacklist at: 2024-05-08 02:50, 2024-05-09 02:50, 2024-05-10 02:50, 2024-05-11 02:50, 2024-05-12 02:50, 2024-05-13 02:50, 2024-05-14 02:50, 2024-05-15 02:50, 2024-05-16 02:50, 2024-05-17 02:50, 2024-05-18 02:50
AbuseIPDB
116.140.208.227 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>IPs performing malicious activity(DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2024-05-13 04:00:01.048000
Was present on blacklist at: 2024-05-08 04:00, 2024-05-09 04:00, 2024-05-10 04:00, 2024-05-11 04:00, 2024-05-12 04:00, 2024-05-13 04:00
Warden events (1103)
2024-05-13
ReconScanning (node.bd32ad): 40
ReconScanning (node.8cbf96): 1
2024-05-12
ReconScanning (node.bd32ad): 214
ReconScanning (node.8cbf96): 9
2024-05-11
ReconScanning (node.bd32ad): 246
ReconScanning (node.8cbf96): 4
2024-05-10
ReconScanning (node.bd32ad): 166
2024-05-09
ReconScanning (node.bd32ad): 226
ReconScanning (node.8cbf96): 5
2024-05-08
ReconScanning (node.bd32ad): 92
2024-05-07
ReconScanning (node.bd32ad): 97
ReconScanning (node.8cbf96): 3
DShield reports (IP summary, reports)
2024-05-02
Number of reports: 46
Distinct targets: 43
2024-05-03
Number of reports: 53
Distinct targets: 53
2024-05-07
Number of reports: 247
Distinct targets: 218
2024-05-08
Number of reports: 199
Distinct targets: 146
2024-05-09
Number of reports: 492
Distinct targets: 412
2024-05-10
Number of reports: 454
Distinct targets: 390
2024-05-11
Number of reports: 520
Distinct targets: 421
2024-05-12
Number of reports: 482
Distinct targets: 394
2024-05-13
Number of reports: 369
Distinct targets: 291
Origin AS
AS4837 - CHINA169-Backbone
BGP Prefix
116.140.192.0/18
geo
China, Guangzhou
🕑 Asia/Shanghai
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
116.128.0.0 - 116.191.255.255
last_activity
2024-05-13 17:54:58
last_warden_event
2024-05-13 17:54:58
rep
0.3214285714285714
reserved_range
0
Shodan's InternetDB
Open ports: 22, 9000
Tags: eol-product
CPEs: cpe:/a:f5:nginx:1.20.1, cpe:/a:openbsd:openssh:6.6.1
ts_added
2024-05-03 05:06:36.124000
ts_last_update
2024-05-18 02:51:21.147000

Warden event timeline

DShield event timeline

Presence on blacklists