IP address


--154.91.196.185
Shodan(more info)
Passive DNS
Tags:
OTX pulses
[6738b3b24bc328fd786fdfb1] 2024-11-16 15:01:06.327000 | Weaponizing FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
Author name:AlienVault
Pulse modified:2024-11-18 20:50:33.035000
Indicator created:2024-11-16 15:01:07
Indicator role:None
Indicator title:
Indicator expiration:2024-12-16 15:00:00
[673bd07763d46cedcc72f43d] 2024-11-18 23:40:39.844000 | Chinese hackers exploit Fortinet VPN zero-day to steal credentials
Author name:AlienVault
Pulse modified:2024-11-19 14:37:52.385000
Indicator created:2024-11-18 23:40:40
Indicator role:None
Indicator title:
Indicator expiration:2024-12-18 23:00:00
Origin AS
AS42960 -
BGP Prefix
154.91.196.0/24
geo
Seychelles
🕑 Indian/Mahe
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
154.80.0.0 - 154.95.255.255
last_activity
2024-11-19 16:46:33.146000
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags:
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:7.6p1
ts_added
2024-11-19 00:46:42.489000
ts_last_update
2025-01-11 00:46:51.448000

Warden event timeline

DShield event timeline

OTX pulses