IP address


.961172.104.233.215172-104-233-215.ip.linodeusercontent.com
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
blocklist.de SSH
172.104.233.215 was recently listed on the blocklist.de SSH blacklist, but currently it is not.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2026-09-27 10:05:00.512000
Was present on blacklist at: 2026-09-19 10:05, 2026-09-19 16:05, 2026-09-19 22:05, 2026-09-20 04:05, 2026-09-20 10:05, 2026-09-20 16:05, 2026-09-20 22:05, 2026-09-21 04:05, 2026-09-21 10:05, 2026-09-21 16:05, 2026-09-21 22:05, 2026-09-22 04:05, 2026-09-22 10:05, 2026-09-22 16:05, 2026-09-22 22:05, 2026-09-23 04:05, 2026-09-23 10:05, 2026-09-23 16:05, 2026-09-23 22:05, 2026-09-24 04:05, 2026-09-24 10:05, 2026-09-24 16:05, 2026-09-25 16:05, 2026-09-25 22:05, 2026-09-26 04:05, 2026-09-26 10:05, 2026-09-26 16:05, 2026-09-26 22:05, 2026-09-27 04:05, 2026-09-27 10:05
AbuseIPDB
172.104.233.215 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 04:00:00.712000
Was present on blacklist at: 2026-09-20 04:00, 2026-09-24 04:00, 2026-09-27 04:00, 2026-09-28 04:00
Echelon CGI script hunt
172.104.233.215 is listed on the Echelon CGI script hunt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning for vulnerable CGI scripts
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:05:04.018000
Was present on blacklist at: 2026-09-28 09:05
Echelon CMS enumeration
172.104.233.215 is listed on the Echelon CMS enumeration blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Content management system discovery and enumeration
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:05:00.912000
Was present on blacklist at: 2026-09-28 09:05
Echelon admin panel hunt
172.104.233.215 is listed on the Echelon admin panel hunt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning for administrative interfaces
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:05:00.876000
Was present on blacklist at: 2026-09-28 09:05
Echelon config file hunt
172.104.233.215 is listed on the Echelon config file hunt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning for exposed configuration files
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:10:00.660000
Was present on blacklist at: 2026-09-28 09:10
Echelon enterprise software probe
172.104.233.215 is listed on the Echelon enterprise software probe blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Probing for enterprise software (Confluence, Jenkins, etc.)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:15:00.224000
Was present on blacklist at: 2026-09-28 09:15
Echelon file upload
172.104.233.215 is listed on the Echelon file upload blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Attempting to upload potentially malicious files
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:15:00.603000
Was present on blacklist at: 2026-09-28 09:15
Echelon router exploit
172.104.233.215 is listed on the Echelon router exploit blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Attempting router firmware exploits (Netgear, D-Link, etc.)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:30:00.498000
Was present on blacklist at: 2026-09-28 09:30
Echelon TLS/SSL crawler
172.104.233.215 is listed on the Echelon TLS/SSL crawler blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:40:00.544000
Was present on blacklist at: 2026-09-28 09:40
Echelon web shell hunt
172.104.233.215 is listed on the Echelon web shell hunt blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: Scanning for web shells (WSO, c99, r57, etc.)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:50:00.546000
Was present on blacklist at: 2026-09-28 09:50
Echelon web crawler
172.104.233.215 is listed on the Echelon web crawler blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:50:00.890000
Was present on blacklist at: 2026-09-28 09:50
Echelon WordPress enumeration
172.104.233.215 is listed on the Echelon WordPress enumeration blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: WordPress user and plugin enumeration
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 09:55:00.495000
Was present on blacklist at: 2026-09-28 09:55

Threat categories

TLRoleCategoryDetails
64 src login protocol: http, ssh, telnet
port: 23, 80
56 src scan port: many
56 src —
37 src exploit

Warden events (1895)
2026-09-29
ReconScanning (node.86eb21): 28
ReconScanning (node.f90c6b): 3
IntrusionUserCompromise (node.cfb4f7): 1
2026-09-28
ReconScanning (node.86eb21): 139
ReconScanning (node.ce2b59): 14
ReconScanning (node.f90c6b): 14
AnomalyTraffic (node.6a1878): 4
2026-09-27
ReconScanning (node.86eb21): 143
ReconScanning (node.f90c6b): 12
ReconScanning (node.ce2b59): 14
AnomalyTraffic (node.6a1878): 4
IntrusionUserCompromise (node.cfb4f7): 11
2026-09-26
ReconScanning (node.86eb21): 142
ReconScanning (node.f90c6b): 16
IntrusionUserCompromise (node.cfb4f7): 12
2026-09-25
ReconScanning (node.86eb21): 141
ReconScanning (node.f90c6b): 12
IntrusionUserCompromise (node.cfb4f7): 11
2026-09-24
ReconScanning (node.86eb21): 118
ReconScanning (node.f90c6b): 12
IntrusionUserCompromise (node.cfb4f7): 1
2026-09-23
ReconScanning (node.86eb21): 141
ReconScanning (node.f90c6b): 17
IntrusionUserCompromise (node.cfb4f7): 20
2026-09-22
ReconScanning (node.86eb21): 140
ReconScanning (node.f90c6b): 19
IntrusionUserCompromise (node.cfb4f7): 12
2026-09-21
ReconScanning (node.86eb21): 140
ReconScanning (node.f90c6b): 13
IntrusionUserCompromise (node.cfb4f7): 12
2026-09-20
ReconScanning (node.86eb21): 142
ReconScanning (node.f90c6b): 14
AnomalyTraffic (node.6a1878): 1
ReconScanning (node.ce2b59): 1
2026-09-19
ReconScanning (node.86eb21): 140
ReconScanning (node.f90c6b): 19
IntrusionUserCompromise (node.cfb4f7): 3
2026-09-18
ReconScanning (node.86eb21): 140
ReconScanning (node.f90c6b): 18
AnomalyTraffic (node.6a1878): 1
IntrusionUserCompromise (node.cfb4f7): 10
2026-09-17
ReconScanning (node.ce2b59): 3
ReconScanning (node.86eb21): 22
AnomalyTraffic (node.6a1878): 3
IntrusionUserCompromise (node.cfb4f7): 10
ReconScanning (node.f90c6b): 2
DShield reports (IP summary, reports)
2026-09-18
Number of reports: 2831
Distinct targets: 1491
2026-09-19
Number of reports: 2831
Distinct targets: 1491
2026-09-21
Number of reports: 2847
Distinct targets: 1489
Origin AS
AS63949 - LINODE-AP
BGP Prefix
172.104.224.0/19
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
172-104-233-215.ip.linodeusercontent.com
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
172.104.0.0 - 172.105.255.255
last_activity
2026-09-29 04:41:19
last_warden_event
2026-09-29 04:41:19
rep
0.9612175190384055
reserved_range
0
Shodan's InternetDB
Open ports: 22, 443, 8181
Tags: self-signed, cloud
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.9p1
ts_added
2026-09-17 19:56:54.828000
ts_last_update
2026-09-29 04:42:23.127000

Warden event timeline

DShield event timeline

Presence on blacklists