IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (12)
- 2026-08-16
-
- ReconScanning (node.86eb21): 1
- 2026-08-15
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 1
- 2026-08-01
-
- ReconScanning (node.368407): 2
- ReconScanning (node.f90c6b): 2
- 2026-07-08
-
- ReconScanning (node.f90c6b): 1
- 2026-06-14
-
- ReconScanning (node.f90c6b): 1
- 2026-06-07
-
- ReconScanning (node.f90c6b): 2
- DShield reports (IP summary, reports)
- 2026-06-06
- Number of reports: 440
- Distinct targets: 220
- 2026-06-07
- Number of reports: 440
- Distinct targets: 220
- 2026-06-26
- Number of reports: 157
- Distinct targets: 157
- 2026-07-02
- Number of reports: 220
- Distinct targets: 220
- 2026-08-09
- Number of reports: 220
- Distinct targets: 220
- 2026-08-10
- Number of reports: 220
- Distinct targets: 220
- 2026-08-20
- Number of reports: 11
- Distinct targets: 10
- 2026-08-21
- Number of reports: 11
- Distinct targets: 10
- 2026-08-28
- Number of reports: 145
- Distinct targets: 145
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 50 | src | scan |
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 121.42.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 121.40.0.0 - 121.43.255.255
- last_activity
- 2026-08-16 03:40:35
- last_warden_event
- 2026-08-16 03:40:35
- rep
- 0.0016360829672673605
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 15, 23, 43, 70, 92, 102, 110, 113, 221, 264, 347, 427, 452, 513, 541, 771, 785, 789, 873, 992, 993, 998, 1023, 1177, 1200, 1451, 1515, 1521, 1650, 1800, 1801, 1951, 2000, 2003, 2008, 2012, 2016, 2030, 2087, 2122, 2154, 2181, 2222, 2224, 2320, 2566, 2568, 2628, 2761, 2762, 3012, 3078, 3102, 3105, 3106, 3113, 3114, 3117, 3126, 3155, 3310, 3316, 3388, 3390, 3560, 3780, 3790, 4022, 4063, 4147, 4157, 4282, 4431, 4461, 4488, 4500, 4646, 4678, 5006, 5009, 5105, 5201, 5222, 5223, 5246, 5351, 5523, 5569, 5605, 5640, 5660, 5905, 5938, 5984, 6000, 6081, 6348, 6650, 6653, 6668, 6755, 6940, 7000, 7083, 7403, 7500, 7548, 7788, 7980, 8021, 8028, 8049, 8071, 8076, 8077, 8094, 8118, 8126, 8128, 8135, 8147, 8152, 8161, 8195, 8200, 8315, 8333, 8441, 8452, 8461, 8494, 8513, 8545, 8554, 8592, 8598, 8686, 8826, 8834, 8853, 8861, 8873, 8884, 8990, 8999, 9030, 9092, 9130, 9132, 9139, 9140, 9147, 9169, 9182, 9215, 9217, 9218, 9333, 9444, 9529, 9530, 9633, 9861, 9901, 9988, 9998, 10001, 10087, 10101, 10134, 10254, 10390, 10399, 10554, 10909, 11112, 11210, 11288, 12000, 12112, 12154, 12215, 12245, 12260, 12280, 12292, 12303, 12305, 12307, 12340, 12345, 12376, 12378, 12387, 12487, 12529, 12566, 16005, 16014, 16018, 16019, 16028, 16029, 16042, 16058, 16080, 16083, 16094, 17182, 17591, 18051, 18081, 18108, 18110, 18225, 18245, 18291, 18556, 20010, 20084, 20880, 21025, 21116, 21244, 21254, 21273, 21275, 21280, 21290, 21317, 21379, 21500, 22556, 22705, 25001, 25004, 25199, 30003, 30011, 30013, 30019, 30131, 30444, 31443, 32764, 34225, 35000, 35089, 35560, 38520, 40000, 40682, 41800, 42045, 42901, 44021, 44158, 45668, 46000, 48013, 48133, 48889, 49080, 49867, 50000, 50080, 50997, 50998, 51005, 51235, 53580, 54022, 54138, 54418, 54545, 54988, 55732, 59997, 60129, 64879
- Tags: honeypot, proxy
- CPEs: cpe:/a:xiongmaitech:uc-httpd:1.0.0, cpe:/a:openbsd:openssh:8.6, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:cisco:ios, cpe:/a:apache:dubbo, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:7.6p1, cpe:/a:cisco:ssh:3524665.35, cpe:/a:openbsd:openssh:X.X, cpe:/o:microsoft:windows, cpe:/a:openbsd:openssh:7.5, cpe:/a:microsoft:message_queuing, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:6.6.1
- ts_added
- 2026-06-07 05:04:43.235000
- ts_last_update
- 2026-08-31 05:10:30.879000
Warden event timeline
DShield event timeline
Presence on blacklists

