IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (8)
- 2026-08-11
-
- ReconScanning (node.ce2b59): 1
- 2026-08-07
-
- ReconScanning (node.86eb21): 1
- 2026-07-24
-
- ReconScanning (node.f90c6b): 2
- ReconScanning (node.368407): 2
- 2026-07-10
-
- ReconScanning (node.f90c6b): 2
- DShield reports (IP summary, reports)
- 2026-07-08
- Number of reports: 214
- Distinct targets: 214
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| No threat category tags assigned | |||
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 121.40.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.40.0.0 - 121.43.255.255
- last_activity
- 2026-08-11 20:46:09
- last_warden_event
- 2026-08-11 20:46:09
- rep
- 0.0
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 13, 17, 53, 70, 86, 98, 113, 179, 453, 488, 513, 554, 666, 789, 831, 853, 873, 886, 987, 993, 1063, 1153, 1198, 1200, 1293, 1433, 1515, 1604, 1650, 1800, 1965, 1988, 1989, 2003, 2008, 2012, 2031, 2056, 2067, 2087, 2095, 2404, 2554, 2985, 3022, 3077, 3082, 3099, 3124, 3131, 3171, 3260, 3268, 3352, 3405, 3410, 3780, 4100, 4157, 4242, 4282, 4355, 4434, 4444, 4500, 4506, 4786, 5004, 5007, 5051, 5172, 5201, 5269, 5346, 5523, 5552, 5907, 5914, 5990, 5991, 6002, 6003, 6352, 6443, 6505, 6588, 6601, 6622, 6667, 7001, 7171, 7415, 7773, 7776, 8058, 8063, 8065, 8075, 8099, 8157, 8200, 8333, 8340, 8401, 8419, 8427, 8500, 8524, 8530, 8549, 8561, 8564, 8588, 8728, 8731, 8745, 8784, 8788, 8790, 8816, 8848, 8854, 8865, 8876, 8878, 8880, 8883, 8905, 8907, 9001, 9010, 9013, 9032, 9040, 9041, 9062, 9068, 9089, 9100, 9127, 9133, 9135, 9151, 9160, 9193, 9196, 9217, 9248, 9306, 9313, 9315, 9454, 9600, 9966, 10001, 10012, 10029, 10033, 10043, 10050, 10533, 10894, 11065, 11184, 11288, 12016, 12140, 12144, 12148, 12161, 12172, 12176, 12193, 12232, 12237, 12247, 12262, 12306, 12325, 12337, 12345, 12346, 12375, 12398, 12413, 12420, 12428, 12436, 12452, 12455, 12462, 12492, 12495, 12498, 12511, 12536, 12549, 12555, 12556, 12574, 13009, 13084, 14130, 14344, 15040, 16004, 16005, 16016, 16054, 16084, 16089, 16097, 17000, 17100, 17780, 18033, 18065, 18101, 18245, 18396, 19233, 19999, 20151, 21237, 21249, 21313, 22403, 22556, 23084, 24808, 25565, 26697, 30011, 30021, 30029, 32764, 35611, 37777, 39256, 41000, 41800, 42225, 42637, 43080, 43676, 44021, 44332, 45032, 45033, 45333, 45788, 47379, 47984, 47990, 48100, 48560, 49193, 50000, 50010, 50042, 50100, 50105, 52605, 52847, 54327, 55000, 55388, 58368, 58901, 60000, 61616, 62078, 62481, 63210, 63256, 63676, 64295
- Tags: honeypot
- CPEs: cpe:/a:cisco:ssh:3524665.35, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:8.2p1, cpe:/a:openbsd:openssh:7.6p1, cpe:/o:microsoft:windows, cpe:/a:openbsd:openssh:6.6.1, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:7.9, cpe:/o:cisco:ios, cpe:/a:openbsd:openssh:7.5, cpe:/a:openbsd:openssh:5.3, cpe:/a:openbsd:openssh:8.0, cpe:/a:eclipse:jetty:9.4.14.v20181114
- ts_added
- 2026-07-09 05:05:15.374000
- ts_last_update
- 2026-08-31 05:09:37.172000
Warden event timeline
DShield event timeline
Presence on blacklists

