IP address
Shodan(more info)

Passive DNS

- Warden events (37)
- 2026-04-24
-
- ReconScanning (node.86eb21): 1
- 2026-04-21
-
- ReconScanning (node.86eb21): 1
- 2026-04-19
-
- ReconScanning (node.86eb21): 2
- 2026-04-18
-
- ReconScanning (node.86eb21): 1
- 2026-04-10
-
- ReconScanning (node.86eb21): 1
- 2026-04-08
-
- ReconScanning (node.f90c6b): 3
- 2026-04-05
-
- ReconScanning (node.86eb21): 1
- 2026-04-03
-
- ReconScanning (node.f90c6b): 3
- ReconScanning (node.86eb21): 1
- 2026-03-25
-
- ReconScanning (node.86eb21): 1
- 2026-03-21
-
- ReconScanning (node.86eb21): 2
- 2026-03-16
-
- ReconScanning (node.86eb21): 1
- 2026-03-15
-
- ReconScanning (node.86eb21): 1
- 2026-03-13
-
- ReconScanning (node.86eb21): 1
- 2026-03-11
-
- ReconScanning (node.86eb21): 1
- 2026-03-07
-
- ReconScanning (node.86eb21): 1
- 2026-03-06
-
- ReconScanning (node.86eb21): 1
- 2026-03-03
-
- ReconScanning (node.86eb21): 1
- 2026-02-27
-
- ReconScanning (node.86eb21): 1
- 2026-02-26
-
- ReconScanning (node.86eb21): 1
- 2026-02-24
-
- ReconScanning (node.86eb21): 1
- 2026-02-19
-
- ReconScanning (node.86eb21): 1
- 2026-02-13
-
- ReconScanning (node.86eb21): 1
- 2026-02-12
-
- ReconScanning (node.86eb21): 1
- 2026-02-11
-
- ReconScanning (node.86eb21): 1
- 2026-02-07
-
- ReconScanning (node.86eb21): 1
- 2026-02-06
-
- ReconScanning (node.86eb21): 1
- 2026-01-31
-
- ReconScanning (node.86eb21): 2
- 2026-01-30
-
- ReconScanning (node.86eb21): 2
- DShield reports (IP summary, reports)
- 2026-02-24
- Number of reports: 20
- Distinct targets: 3
- 2026-02-25
- Number of reports: 20
- Distinct targets: 3
- 2026-02-26
- Number of reports: 68
- Distinct targets: 10
- 2026-03-03
- Number of reports: 24
- Distinct targets: 4
- 2026-03-04
- Number of reports: 68
- Distinct targets: 9
- 2026-03-05
- Number of reports: 68
- Distinct targets: 9
- 2026-03-09
- Number of reports: 16
- Distinct targets: 3
- 2026-03-11
- Number of reports: 68
- Distinct targets: 10
- 2026-03-17
- Number of reports: 60
- Distinct targets: 9
- 2026-03-25
- Number of reports: 84
- Distinct targets: 11
- 2026-03-26
- Number of reports: 84
- Distinct targets: 11
- 2026-04-02
- Number of reports: 56
- Distinct targets: 9
- 2026-04-09
- Number of reports: 60
- Distinct targets: 10
- 2026-04-20
- Number of reports: 24
- Distinct targets: 6
- 2026-04-22
- Number of reports: 76
- Distinct targets: 11
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 35 | src | scan |
- Origin AS
- AS136258 - ONEPROVIDER-AS
- BGP Prefix
- 185.213.23.0/24
- geo
- Norway, Oslo
- 🕑 Europe/Oslo
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 185.213.20.0 - 185.213.23.255
- last_activity
- 2026-04-24 03:03:55
- last_warden_event
- 2026-04-24 03:03:55
- rep
- 0.1
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 13, 17, 19, 21, 25, 26, 37, 38, 43, 49, 70, 79, 80, 81, 84, 90, 91, 96, 97, 102, 104, 110, 111, 119, 135, 139, 143, 175, 179, 192, 199, 221, 243, 264, 340, 343, 389, 444, 446, 448, 452, 465, 487, 502, 503, 541, 548, 587, 591, 593, 631, 636, 666, 771, 789, 873, 902, 947, 995, 1024, 1099, 1103, 1167, 1234, 1311, 1337, 1365, 1400, 1414, 1443, 1454, 1471, 1515, 1521, 1599, 1604, 1741, 1801, 1925, 1926, 1935, 1951, 1954, 1967, 1973, 1977, 1978, 1982, 1990, 2008, 2016, 2062, 2067, 2068, 2079, 2082, 2083, 2086, 2087, 2096, 2100, 2121, 2122, 2154, 2181, 2200, 2222, 2259, 2266, 2345, 2404, 2453, 2455, 2554, 2562, 2569, 2570, 2599, 2602, 2628, 2650, 2761, 2762, 2806, 3000, 3001, 3006, 3009, 3011, 3017, 3022, 3047, 3060, 3073, 3082, 3086, 3107, 3116, 3131, 3135, 3139, 3140, 3143, 3150, 3151, 3154, 3173, 3192, 3260, 3269, 3299, 3301, 3306, 3310, 3333, 3345, 3365, 3388, 3389, 3406, 3407, 3521, 3541, 3542, 3568, 3569, 3689, 3749, 3780, 3793, 4000, 4063, 4150, 4157, 4159, 4242, 4282, 4300, 4321, 4369, 4432, 4433, 4434, 4439, 4443, 4444, 4445, 4451, 4457, 4459, 4461, 4463, 4477, 4500, 4506, 4510, 4521, 4664, 4782, 4786, 4840, 4899, 4911, 4949, 5000, 5005, 5025, 5190, 5209, 5222, 5224, 5225, 5252, 5253, 5257, 5266, 5269, 5275, 5278, 5357, 5432, 5433, 5435, 5555, 5594, 5595, 5600, 5605, 5630, 5647, 5672, 5800, 5901, 5915, 5919, 5985, 5994, 6001, 6011, 6022, 6080, 6100, 6161, 6264, 6405, 6432, 6443, 6500, 6544, 6580, 6588, 6590, 6622, 6666, 6686, 6697, 6700, 7001, 7007, 7021, 7078, 7084, 7087, 7090, 7102, 7171, 7302, 7415, 7434, 7443, 7548, 7775, 7777, 7779, 7790, 7900, 7989, 8000, 8001, 8009, 8010, 8013, 8028, 8032, 8037, 8038, 8041, 8046, 8048, 8055, 8060, 8069, 8073, 8077, 8083, 8087, 8089, 8090, 8091, 8098, 8099, 8112, 8124, 8125, 8126, 8131, 8138, 8141, 8146, 8147, 8161, 8181, 8183, 8188, 8192, 8194, 8197, 8200, 8319, 8333, 8415, 8432, 8443, 8456, 8481, 8484, 8485, 8515, 8523, 8525, 8540, 8545, 8554, 8556, 8567, 8575, 8584, 8704, 8709, 8764, 8789, 8800, 8824, 8827, 8834, 8835, 8838, 8845, 8850, 8855, 8857, 8871, 8876, 8879, 8880, 8883, 8888, 8889, 8899, 8900, 8915, 9000, 9001, 9002, 9009, 9011, 9013, 9015, 9022, 9024, 9026, 9031, 9034, 9037, 9051, 9053, 9060, 9076, 9078, 9080, 9081, 9083, 9087, 9088, 9090, 9091, 9095, 9097, 9100, 9110, 9113, 9121, 9135, 9138, 9146, 9151, 9168, 9171, 9175, 9182, 9191, 9200, 9202, 9203, 9236, 9247, 9248, 9289, 9295, 9315, 9333, 9350, 9351, 9387, 9399, 9418, 9443, 9445, 9447, 9456, 9513, 9515, 9548, 9550, 9595, 9600, 9633, 9779, 9797, 9800, 9869, 9876, 9899, 9901, 9902, 9939, 9944, 9981, 9992, 9998, 9999
- Tags: honeypot
- CPEs: cpe:/a:openbsd:openssh:8.9p1, cpe:/o:canonical:ubuntu_linux
- ts_added
- 2024-04-28 03:43:08.215000
- ts_last_update
- 2026-04-25 22:13:33.999000
Warden event timeline
DShield event timeline

