IP address


--121.160.102.68
Shodan(more info)
Passive DNS
Tags:
OTX pulses
[691d46b4135d2acc04876592] 2025-11-19 04:25:24.498000 | ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet
Author name:AlienVault
Pulse modified:2025-11-19 08:38:39.283000
Indicator created:2025-11-19 04:25:25
Indicator role:None
Indicator title:
Indicator expiration:2025-12-19 04:00:00
Origin AS
AS4766 - KIXS-AS-KR KIXS-AS-KR-KR
BGP Prefix
121.160.0.0/13
geo
South Korea, Dongdaemun
🕑 Asia/Seoul
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
121.160.0.0 - 121.191.255.255
last_activity
2025-11-19 12:40:19.262000
reserved_range
0
Shodan's InternetDB
Open ports: 111, 443, 1883, 2222, 8188
Tags: self-signed, ai
CPEs: cpe:/a:eclipse:mosquitto:1.6.9, cpe:/a:comfy:comfyui:0.3.66, cpe:/a:python:python:3.11, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.2p1
ts_added
2025-11-19 12:40:19.269000
ts_last_update
2025-12-24 12:40:21.314000

Warden event timeline

DShield event timeline

OTX pulses