IP address


.001121.40.46.35
Shodan(more info)
Passive DNS
Tags:
IP blacklists
blocklist.de mail
121.40.46.35 is listed on the blocklist.de mail blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing Mail attacks.
Type of feed: primary (feed detail page)

Last checked at: 2026-08-23 16:05:00.412000
Was present on blacklist at: 2026-08-21 22:05, 2026-08-22 04:05, 2026-08-22 10:05, 2026-08-22 16:05, 2026-08-22 22:05, 2026-08-23 04:05, 2026-08-23 10:05, 2026-08-23 16:05

Threat categories

TLRoleCategoryDetails
40 src
25 src scan port: many

Warden events (3)
2026-08-21
ReconScanning (node.ce2b59): 1
2026-08-08
ReconScanning (node.86eb21): 2
DShield reports (IP summary, reports)
2026-08-11
Number of reports: 220
Distinct targets: 220
Origin AS
AS37963 - CNNIC-ALIBABA-CN-NET-AP
BGP Prefix
121.40.0.0/15
geo
China, Hangzhou
🕑 Asia/Shanghai
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
121.40.0.0 - 121.43.255.255
last_activity
2026-08-21 12:49:48
last_warden_event
2026-08-21 12:49:48
rep
0.0007472069585939822
reserved_range
0
Shodan's InternetDB
Open ports: 15, 17, 37, 49, 53, 110, 179, 204, 389, 441, 513, 548, 554, 1080, 1177, 1230, 1283, 1433, 1515, 1723, 1926, 1967, 1974, 2008, 2060, 2150, 2154, 2271, 2289, 2323, 2332, 2345, 2404, 2528, 2552, 2850, 3001, 3012, 3073, 3117, 3121, 3124, 3143, 3260, 3299, 3301, 3400, 3566, 3841, 4064, 4157, 4282, 4369, 4434, 4443, 4444, 4451, 4771, 4899, 4949, 4993, 5010, 5025, 5093, 5234, 5250, 5252, 5267, 5268, 5280, 5435, 5439, 5609, 5672, 5905, 5938, 6008, 6009, 6060, 6070, 6432, 6666, 6667, 6668, 7050, 7057, 7083, 7171, 7415, 7801, 8009, 8030, 8035, 8048, 8059, 8075, 8081, 8083, 8099, 8100, 8102, 8124, 8126, 8130, 8141, 8157, 8185, 8190, 8243, 8381, 8406, 8465, 8528, 8545, 8549, 8574, 8596, 8641, 8745, 8782, 8811, 8815, 8818, 9030, 9061, 9076, 9160, 9187, 9220, 9306, 9310, 9333, 9376, 9444, 9633, 9761, 9872, 9876, 9902, 9994, 10032, 10045, 10048, 10134, 10348, 10477, 10480, 10533, 10810, 10911, 10933, 11027, 11112, 11210, 11300, 11920, 12088, 12122, 12164, 12194, 12247, 12261, 12274, 12312, 12320, 12342, 12352, 12421, 12453, 12477, 12479, 12490, 14330, 14344, 15040, 16000, 16001, 16020, 16039, 16041, 16046, 16070, 16071, 16079, 16404, 17082, 17775, 18017, 18032, 18047, 18054, 18090, 18104, 18105, 18245, 18264, 18443, 19000, 20547, 21244, 21245, 21247, 21256, 21275, 21312, 21379, 22022, 23047, 25008, 27017, 27086, 30007, 30479, 31444, 31525, 32374, 32800, 35212, 35241, 38880, 39001, 41010, 42424, 43009, 44674, 44818, 45685, 47984, 48988, 49686, 50112, 52200, 55350, 57778, 60023, 60129, 61721, 63045, 63256, 63263
Tags: honeypot
CPEs: cpe:/o:microsoft:windows, cpe:/a:openbsd:openssh:7.9, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/a:openbsd:openssh:7.2p2, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.0, cpe:/a:eset:nod32_antivirus:99, cpe:/a:openbsd:openssh:7.4, cpe:/a:apache:subversion, cpe:/a:openbsd:openssh:7.5
ts_added
2026-08-08 17:22:00.231000
ts_last_update
2026-08-31 17:22:10.452000

Warden event timeline

DShield event timeline

Presence on blacklists