IP address


.002121.40.44.247
Shodan(more info)
Passive DNS
Tags:
IP blacklists
blocklist.de SSH
121.40.44.247 is listed on the blocklist.de SSH blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2026-08-10 16:05:00.427000
Was present on blacklist at: 2026-08-08 22:05, 2026-08-09 04:05, 2026-08-09 10:05, 2026-08-09 16:05, 2026-08-09 22:05, 2026-08-10 04:05, 2026-08-10 10:05, 2026-08-10 16:05
Spamhaus XBL CBL
121.40.44.247 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2026-08-28 05:08:48.833000
Was present on blacklist at: 2026-08-28 05:08

Threat categories

TLRoleCategoryDetails
25 src scan port: many

Warden events (12)
2026-08-26
ReconScanning (node.ce2b59): 1
2026-08-21
ReconScanning (node.86eb21): 1
2026-08-08
ReconScanning (node.86eb21): 1
2026-08-06
ReconScanning (node.86eb21): 1
ReconScanning (node.f90c6b): 1
2026-08-01
ReconScanning (node.86eb21): 2
2026-07-17
ReconScanning (node.f90c6b): 2
ReconScanning (node.368407): 2
2026-07-06
ReconScanning (node.f90c6b): 1
DShield reports (IP summary, reports)
2026-07-02
Number of reports: 54
Distinct targets: 27
2026-07-31
Number of reports: 30
Distinct targets: 30
2026-08-01
Number of reports: 30
Distinct targets: 30
2026-08-08
Number of reports: 27
Distinct targets: 27
2026-08-09
Number of reports: 440
Distinct targets: 220
2026-08-10
Number of reports: 440
Distinct targets: 220
Origin AS
AS37963 - CNNIC-ALIBABA-CN-NET-AP
BGP Prefix
121.40.0.0/15
geo
China, Hangzhou
🕑 Asia/Shanghai
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
121.40.0.0 - 121.43.255.255
last_activity
2026-08-26 02:15:24
last_warden_event
2026-08-26 02:15:24
rep
0.0024284226154304145
reserved_range
0
Shodan's InternetDB
Open ports: 37, 79, 119, 135, 515, 666, 1234, 1343, 1444, 1604, 2002, 2008, 2181, 2351, 2404, 2598, 3094, 3114, 3136, 3703, 3790, 4157, 4321, 4333, 4449, 4899, 5115, 5238, 5243, 5275, 5603, 6000, 6379, 6605, 6666, 6779, 7000, 7444, 7500, 8009, 8282, 8291, 8333, 8532, 8577, 9161, 9218, 9500, 9811, 9914, 10050, 10397, 10894, 10911, 12159, 12534, 16060, 16067, 18011, 18092, 20080, 20242, 20446, 21261, 23538, 25005, 25084, 28365, 28450, 35524, 36335, 44520, 45333, 48019, 60023, 63979
Tags: proxy, honeypot
CPEs: cpe:/a:openbsd:openssh:8.6, cpe:/a:openbsd:openssh:7.4, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.0, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/o:microsoft:windows, cpe:/a:openbsd:openssh:7.5
ts_added
2026-07-03 05:04:29.690000
ts_last_update
2026-08-31 05:12:12.843000

Warden event timeline

DShield event timeline

Presence on blacklists