IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (10)
- 2026-08-06
-
- ReconScanning (node.86eb21): 1
- ReconScanning (node.ce2b59): 1
- ReconScanning (node.f90c6b): 2
- 2026-07-12
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 1
- 2026-07-07
-
- ReconScanning (node.f90c6b): 1
- 2026-07-03
-
- ReconScanning (node.86eb21): 1
- 2026-06-06
-
- ReconScanning (node.f90c6b): 1
- DShield reports (IP summary, reports)
- 2026-06-19
- Number of reports: 674
- Distinct targets: 221
- 2026-08-06
- Number of reports: 137
- Distinct targets: 137
- 2026-08-07
- Number of reports: 137
- Distinct targets: 137
- 2026-08-16
- Number of reports: 219
- Distinct targets: 219
- 2026-08-28
- Number of reports: 538
- Distinct targets: 222
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 50 | src | scan |
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 121.42.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.40.0.0 - 121.43.255.255
- last_activity
- 2026-08-06 20:37:28
- last_warden_event
- 2026-08-06 20:37:28
- rep
- 0.006997768227433032
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 13, 15, 17, 21, 25, 43, 49, 51, 53, 90, 111, 119, 122, 175, 179, 190, 195, 211, 264, 389, 443, 447, 465, 513, 541, 548, 555, 666, 785, 789, 833, 873, 902, 987, 992, 995, 1080, 1177, 1234, 1453, 1515, 1521, 1604, 1800, 1801, 1883, 1951, 1957, 1962, 2000, 2001, 2008, 2021, 2031, 2052, 2059, 2067, 2154, 2200, 2233, 2332, 2351, 2404, 2553, 2561, 2598, 2761, 2979, 3018, 3042, 3058, 3062, 3082, 3137, 3153, 3154, 3174, 3181, 3260, 3268, 3299, 3388, 3580, 4103, 4157, 4160, 4190, 4282, 4321, 4369, 4437, 4444, 4502, 4505, 4528, 4530, 4786, 4808, 4899, 5007, 5009, 5010, 5025, 5180, 5222, 5232, 5269, 5660, 5672, 5698, 5858, 5903, 5988, 6003, 6007, 6264, 6511, 6622, 6633, 6661, 6666, 6667, 6697, 6700, 6748, 7171, 7173, 7218, 7272, 7403, 7415, 7493, 7634, 8007, 8009, 8033, 8034, 8045, 8047, 8079, 8087, 8092, 8093, 8099, 8115, 8126, 8149, 8154, 8156, 8158, 8162, 8166, 8170, 8181, 8182, 8185, 8291, 8315, 8350, 8384, 8432, 8456, 8466, 8475, 8481, 8504, 8506, 8524, 8545, 8560, 8575, 8580, 8584, 8703, 8723, 8766, 8789, 8822, 8851, 8878, 8880, 8881, 8883, 8908, 8990, 9067, 9091, 9100, 9102, 9106, 9119, 9130, 9132, 9140, 9158, 9189, 9196, 9209, 9210, 9222, 9246, 9252, 9283, 9292, 9300, 9410, 9418, 9600, 9633, 9696, 9700, 9872, 9876, 9898, 9909, 9999, 10240, 10554, 10726, 11000, 11180, 11572, 11882, 12000, 12120, 12124, 12143, 12148, 12149, 12182, 12193, 12251, 12280, 12345, 12352, 12375, 12400, 12439, 12440, 12456, 12457, 12460, 12461, 12470, 12495, 12544, 12546, 12569, 12572, 12576, 14265, 14344, 16049, 16072, 16087, 17000, 17010, 17070, 17443, 18033, 18037, 18047, 18060, 18064, 18083, 18090, 18099, 18245, 18791, 19160, 20080, 20147, 20151, 20256, 20600, 21002, 21025, 21282, 21289, 21328, 21379, 22103, 22705, 22910, 25001, 25003, 25010, 25565, 26766, 27017, 27105, 28015, 29798, 30003, 30614, 32200, 32444, 32764, 33389, 35101, 36061, 37777, 41284, 42003, 44307, 44308, 44333, 44399, 44812, 44818, 45002, 45788, 45868, 47817, 48998, 50000, 50012, 50500, 51235, 53909, 54490, 55128, 55555, 55920, 56991, 57743, 60443, 61613, 61616, 62078, 63260
- Tags: proxy, honeypot, eol-product
- CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/o:microsoft:qotd::::en, cpe:/a:cisco:ssh:3524665.35, cpe:/a:openbsd:openssh:7.9, cpe:/a:openbsd:openssh:8.0, cpe:/a:openbsd:openssh:X.X, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:7.2p2, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:cisco:ios, cpe:/h:dlink:dls-2750u, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/a:openbsd:openssh:5.3, cpe:/a:openbsd:openssh:6.6.1, cpe:/o:microsoft:windows, cpe:/o:hp:hp-ux, cpe:/a:openbsd:openssh:7.6p1, cpe:/a:f5:nginx:1.22.1
- ts_added
- 2026-02-28 05:05:17.070000
- ts_last_update
- 2026-08-31 05:09:52.724000
Warden event timeline
DShield event timeline
Presence on blacklists

