IP address


.558185.73.23.162goose.softsec.ruhr-uni-bochum.de
Shodan(more info)
Passive DNS
Tags: Residential proxy
IP blacklists
AbuseIPDB
185.73.23.162 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-17 04:00:00.478000
Was present on blacklist at: 2026-09-16 04:00, 2026-09-17 04:00
Echelon TLS/SSL crawler
185.73.23.162 is listed on the Echelon TLS/SSL crawler blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-09-16 09:40:00.591000
Was present on blacklist at: 2026-09-16 09:40
Echelon web crawler
185.73.23.162 is listed on the Echelon web crawler blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-09-16 09:50:00.883000
Was present on blacklist at: 2026-09-16 09:50

Threat categories

TLRoleCategoryDetails
80 src scan port: 80, 443
48 src

Warden events (91)
2026-09-16
ReconScanning (node.ce2b59): 7
AnomalyTraffic (node.6a1878): 9
ReconScanning (node.368407): 16
ReconScanning (node.4dc198): 16
2026-09-15
AnomalyTraffic (node.6a1878): 4
ReconScanning (node.ce2b59): 2
ReconScanning (node.368407): 8
ReconScanning (node.4dc198): 8
2026-09-14
AnomalyTraffic (node.6a1878): 4
ReconScanning (node.4dc198): 8
ReconScanning (node.368407): 8
ReconScanning (node.ce2b59): 1
DShield reports (IP summary, reports)
2026-09-14
Number of reports: 309
Distinct targets: 211
2026-09-15
Number of reports: 309
Distinct targets: 211
2026-09-16
Number of reports: 1272
Distinct targets: 300
Residential proxy info (data provided by Layer3 Intel)
Last seen: 2026-08-16 05:40:56}
Percent days seen: 16 %
Networks: OXYLABS, INFATICA, DECODO, PACKETSTREAM, WEBSHARE, STRIKEPROXY, PROXYRACK, BOTTINGTOOLS, ANYIP, 711PROXY, MASKIFY, LEMONBRIGHT, BYTEPROXIES, KOOKEY, EVOMI, GEONODE, GONZOPROXY, BYTEFUL, FLASHPROXY, PROXY-SELLER
Details: https://layer3intel.com/context/185.73.23.162
Origin AS
AS29484 - RUB-AS
BGP Prefix
185.73.23.0/24
geo
Germany
🕑 Europe/Berlin
hostname
goose.softsec.ruhr-uni-bochum.de
Address block ('inetnum' or 'NetRange' in whois database)
185.73.20.0 - 185.73.23.255
last_activity
2026-09-16 21:01:53
last_warden_event
2026-09-16 21:01:53
rep
0.5576718638276825
reserved_range
0
Shodan's InternetDB
Open ports: 22222
Tags: scanner
CPEs: cpe:/o:debian:debian_linux, cpe:/o:linux:linux_kernel, cpe:/a:openbsd:openssh:10.0p2
ts_added
2026-09-14 20:44:45.220000
ts_last_update
2026-09-17 05:00:26.177000

Warden event timeline

DShield event timeline

Presence on blacklists