IP address
Shodan(more info)

Passive DNS

- OTX pulses
-
[6a5e7a9e8b20b763327b0d2d] 2026-07-20 19:44:30.537000 | Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Author name: AlienVault Pulse modified: 2026-07-21 10:23:15.291000 Indicator created: 2026-07-20 19:44:31 Indicator role: None Indicator title: Indicator expiration: 2026-08-19 19:00:00
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| No threat category tags assigned | |||
- Origin AS
- AS26666 - INTERSERVER-LAX
- BGP Prefix
- 163.245.192.0/21
- geo
- United States
- 🕑 America/Chicago
- hostname
- vps3501949.trouble-free.net
- Address block ('inetnum' or 'NetRange' in whois database)
- 163.245.0.0 - 163.245.255.255
- last_activity
- 2026-07-24 14:41:01.717000
- rep
- 0.0
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 21, 22, 25, 53, 80, 110, 143, 443, 465, 587, 993, 995, 2222, 3389
- Tags: starttls
- CPEs: cpe:/a:exim:exim:4.99.4, cpe:/a:apache:http_server:2, cpe:/a:openbsd:openssh:9.9, cpe:/a:pureftpd:pure-ftpd
- ts_added
- 2026-07-24 14:41:01.945000
- ts_last_update
- 2026-09-12 14:41:10.767000
Warden event timeline
DShield event timeline
OTX pulses

