IP address
Shodan(more info)

Passive DNS

- OTX pulses
-
[691d46b4135d2acc04876592] 2025-11-19 04:25:24.498000 | ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet
Author name: AlienVault Pulse modified: 2025-11-19 08:38:39.283000 Indicator created: 2025-11-19 04:25:25 Indicator role: None Indicator title: Indicator expiration: 2025-12-19 04:00:00
- Origin AS
- AS4766 - KIXS-AS-KR KIXS-AS-KR-KR
- BGP Prefix
- 121.160.0.0/13
- geo
- South Korea, Dongdaemun
- 🕑 Asia/Seoul
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.160.0.0 - 121.191.255.255
- last_activity
- 2025-11-19 12:40:19.262000
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 111, 443, 1883, 2222, 8188
- Tags: self-signed, ai
- CPEs: cpe:/a:eclipse:mosquitto:1.6.9, cpe:/a:comfy:comfyui:0.3.66, cpe:/a:python:python:3.11, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.2p1
- ts_added
- 2025-11-19 12:40:19.269000
- ts_last_update
- 2025-12-24 12:40:21.314000
Warden event timeline
DShield event timeline
OTX pulses

