IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (14)
- 2026-08-14
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 1
- 2026-08-08
-
- ReconScanning (node.f90c6b): 1
- 2026-08-01
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 2
- 2026-07-18
-
- ReconScanning (node.86eb21): 1
- 2026-07-07
-
- ReconScanning (node.f90c6b): 1
- 2026-07-06
-
- ReconScanning (node.f90c6b): 1
- 2026-06-15
-
- ReconScanning (node.ce2b59): 1
- 2026-06-08
-
- ReconScanning (node.f90c6b): 2
- DShield reports (IP summary, reports)
- 2026-06-08
- Number of reports: 440
- Distinct targets: 220
- 2026-07-31
- Number of reports: 147
- Distinct targets: 147
- 2026-08-01
- Number of reports: 147
- Distinct targets: 147
- 2026-08-08
- Number of reports: 880
- Distinct targets: 440
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| No threat category tags assigned | |||
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 121.42.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.40.0.0 - 121.43.255.255
- last_activity
- 2026-08-14 08:56:43
- last_warden_event
- 2026-08-14 08:56:43
- rep
- 0.0
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 13, 15, 26, 49, 53, 66, 79, 102, 111, 119, 221, 340, 447, 450, 465, 513, 548, 672, 771, 873, 888, 902, 1153, 1364, 1377, 1433, 1515, 1521, 1723, 1800, 1801, 1830, 1958, 1962, 1972, 1979, 2000, 2001, 2002, 2008, 2012, 2021, 2121, 2220, 2222, 2345, 2404, 2553, 2850, 3001, 3014, 3022, 3050, 3084, 3093, 3109, 3118, 3135, 3149, 3179, 3211, 3299, 3385, 3388, 3403, 3408, 3410, 3792, 4000, 4063, 4242, 4282, 4321, 4369, 4439, 4444, 4550, 4643, 4899, 5001, 5025, 5135, 5150, 5201, 5252, 5488, 5599, 5640, 5858, 5905, 5906, 6007, 6020, 6262, 6379, 6590, 6668, 6697, 6699, 7000, 7218, 7302, 7403, 7415, 7634, 8009, 8067, 8094, 8105, 8126, 8162, 8170, 8192, 8333, 8424, 8450, 8500, 8501, 8540, 8545, 8570, 8575, 8594, 8703, 8728, 8808, 8811, 8819, 8825, 8850, 8883, 8993, 9015, 9026, 9050, 9062, 9110, 9134, 9154, 9156, 9160, 9195, 9206, 9304, 9418, 9633, 9743, 9761, 9922, 10004, 10036, 10134, 10255, 10443, 11001, 11112, 11596, 12110, 12121, 12159, 12198, 12219, 12220, 12236, 12256, 12282, 12322, 12325, 12345, 12368, 12390, 12465, 12474, 12488, 12505, 12510, 12515, 12563, 12574, 12581, 12615, 13082, 13422, 14265, 14402, 15123, 15151, 15474, 15554, 16007, 16047, 16049, 16065, 16103, 17020, 18021, 18038, 18050, 18051, 18097, 18181, 19082, 19902, 19999, 20000, 20100, 20184, 20497, 20880, 21001, 21234, 21298, 21319, 22556, 23023, 23675, 25000, 25001, 25405, 25661, 27017, 27647, 30002, 30588, 30687, 35000, 35547, 35845, 37777, 38671, 39109, 40029, 41800, 42272, 44158, 44301, 44302, 44400, 46318, 48540, 48888, 49519, 50000, 50012, 50100, 50101, 50113, 50805, 51235, 52010, 53832, 54138, 54327, 54590, 54753, 55550, 57785, 57788, 59012, 59853, 60129, 60390, 61498, 61616, 62865, 63256, 63599
- Tags: eol-product, honeypot
- CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:X.X, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:openbsd:openssh:7.2p2, cpe:/a:openbsd:openssh:7.4rnn, cpe:/a:openbsd:openssh:7.6p1, cpe:/o:hp:hp-ux, cpe:/a:openbsd:openssh:7.9, cpe:/a:apache:dubbo, cpe:/a:openbsd:openssh:8.6, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/a:openbsd:openssh:7.4, cpe:/o:cisco:ios, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:microsoft:windows, cpe:/a:microsoft:message_queuing, cpe:/a:cisco:ssh:3524665.35, cpe:/a:f5:nginx:1.22.1, cpe:/a:eset:nod32_antivirus:99, cpe:/a:openbsd:openssh:5.3
- ts_added
- 2026-04-14 05:05:14.857000
- ts_last_update
- 2026-08-31 05:13:35.051000
Warden event timeline
DShield event timeline
Presence on blacklists

