IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (8)
- 2026-08-26
-
- ReconScanning (node.ce2b59): 1
- 2026-08-08
-
- ReconScanning (node.86eb21): 1
- 2026-08-07
-
- ReconScanning (node.86eb21): 1
- 2026-08-06
-
- ReconScanning (node.86eb21): 1
- 2026-08-05
-
- ReconScanning (node.86eb21): 1
- 2026-08-01
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 1
- DShield reports (IP summary, reports)
- 2026-08-06
- Number of reports: 16
- Distinct targets: 16
- 2026-08-07
- Number of reports: 16
- Distinct targets: 16
- 2026-08-14
- Number of reports: 48
- Distinct targets: 24
- 2026-08-15
- Number of reports: 48
- Distinct targets: 24
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 25 | src | scan | port: many |
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 121.42.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.40.0.0 - 121.43.255.255
- last_activity
- 2026-08-26 03:02:21
- last_warden_event
- 2026-08-26 03:02:21
- rep
- 0.0016812156568364323
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 21, 23, 98, 113, 221, 264, 311, 485, 502, 515, 782, 789, 873, 887, 995, 1023, 1051, 1080, 1099, 1177, 1190, 1800, 1911, 1988, 1990, 2000, 2002, 2008, 2031, 2068, 2069, 2080, 2081, 2087, 2101, 2103, 2211, 2271, 2332, 2345, 2443, 2551, 2650, 2709, 2762, 2806, 3006, 3017, 3064, 3089, 3097, 3134, 3145, 3181, 3270, 3301, 3310, 3352, 3551, 3553, 3950, 4010, 4022, 4064, 4100, 4157, 4282, 4321, 4369, 4438, 4440, 4545, 5009, 5172, 5222, 5225, 5278, 5435, 5542, 5552, 5567, 5597, 5858, 5984, 5996, 6001, 6002, 6308, 6379, 6503, 6514, 6560, 6588, 7050, 7085, 7218, 7443, 7687, 7700, 8047, 8052, 8087, 8105, 8132, 8161, 8291, 8340, 8383, 8412, 8445, 8523, 8600, 8790, 8847, 8854, 8863, 9015, 9091, 9116, 9160, 9166, 9196, 9249, 9250, 9333, 9398, 9399, 9418, 9488, 9955, 9990, 9999, 10004, 10026, 10027, 10255, 10554, 10894, 11300, 11401, 12123, 12135, 12136, 12141, 12163, 12194, 12241, 12266, 12288, 12323, 12345, 12362, 12375, 12395, 12419, 12443, 12452, 12462, 12490, 12503, 12538, 12550, 12554, 12578, 12586, 14265, 15084, 15555, 16011, 16043, 16053, 16082, 16098, 16667, 18030, 18036, 18062, 18079, 18443, 19222, 20053, 20500, 20547, 20880, 21025, 21200, 21259, 21267, 21288, 21309, 21318, 21379, 21443, 22705, 23182, 25001, 25005, 25565, 29182, 30894, 31001, 32764, 33060, 36921, 36982, 40980, 41800, 44164, 44304, 45667, 47199, 50085, 50995, 52200, 59029, 60129, 60443, 63210, 63443, 65063
- Tags: honeypot
- CPEs: cpe:/a:apache:dubbo, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:microsoft:windows, cpe:/a:realvnc:realvnc:::enterprise, cpe:/a:openbsd:openssh:X.X, cpe:/a:apache:subversion, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:openbsd:openssh:8.0, cpe:/a:vsftpd:vsftpd:3.0.2, cpe:/a:cisco:ssh:3524665.35, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:7.2p2, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/o:cisco:ios
- ts_added
- 2026-08-01 02:18:57.473000
- ts_last_update
- 2026-08-31 02:19:00.068000
Warden event timeline
DShield event timeline
Presence on blacklists

