IP address


.630154.93.60.226
Shodan(more info)
Passive DNS
Tags: Scanner

Threat categories

TLRoleCategoryDetails
58 src scan port: 23

Warden events (369)
2026-05-10
ReconScanning (node.ce2b59): 8
ReconScanning (node.9c1411): 1
2026-05-09
ReconScanning (node.ce2b59): 32
ReconScanning (node.9c1411): 17
2026-05-08
ReconScanning (node.9c1411): 26
ReconScanning (node.ce2b59): 31
2026-05-07
ReconScanning (node.9c1411): 26
ReconScanning (node.ce2b59): 31
2026-05-06
ReconScanning (node.9c1411): 53
ReconScanning (node.ce2b59): 31
2026-05-05
ReconScanning (node.ce2b59): 29
ReconScanning (node.9c1411): 29
2026-05-04
ReconScanning (node.ce2b59): 4
2026-05-03
ReconScanning (node.ce2b59): 15
2026-05-02
ReconScanning (node.ce2b59): 22
2026-05-01
ReconScanning (node.ce2b59): 3
2026-04-30
ReconScanning (node.ce2b59): 11
DShield reports (IP summary, reports)
2026-05-01
Number of reports: 770
Distinct targets: 4
2026-05-02
Number of reports: 41
Distinct targets: 5
2026-05-03
Number of reports: 41
Distinct targets: 5
2026-05-09
Number of reports: 29
Distinct targets: 6
Origin AS
AS138915 - KAOPU-HK
BGP Prefix
154.93.60.0/24
geo
Seychelles
🕑 Indian/Mahe
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
154.80.0.0 - 154.95.255.255
last_activity
2026-05-10 05:39:45
last_warden_event
2026-05-10 05:39:45
rep
0.6301515125093006
reserved_range
0
Shodan's InternetDB
Open ports: 22, 53, 80, 110, 111, 143, 465, 587, 993, 995, 2083, 2087, 3306
Tags: starttls, database, self-signed
CPEs: cpe:/a:openbsd:openssh:7.4, cpe:/a:cpanel:whm, cpe:/a:oracle:mysql, cpe:/a:exim:exim:4.95, cpe:/a:apache:http_server, cpe:/a:cpanel:cpanel
ts_added
2026-04-30 18:32:28.773000
ts_last_update
2026-05-10 05:41:32.708000

Warden event timeline

DShield event timeline