IP address
Shodan(more info)

Passive DNS

- IP blacklists
- DShield reports (IP summary, reports)
- 2025-04-12
- Number of reports: 54
- Distinct targets: 21
- 2025-04-22
- Number of reports: 16
- Distinct targets: 16
- 2025-05-07
- Number of reports: 34
- Distinct targets: 23
- 2025-05-10
- Number of reports: 12
- Distinct targets: 6
- OTX pulses
-
[682b238c0f0191f6982d0eef] 2025-05-19 12:26:52.734000 | RDP honeypot logs for 2025/05/19
Author name: jnazario Pulse modified: 2025-05-19 12:26:52.734000 Indicator created: 2025-05-19 12:26:53 Indicator role: None Indicator title: Indicator expiration: 2025-06-18 12:00:00 [6831bb41a28f3acc182994dc] 2025-05-24 12:27:45.354000 | RDP honeypot logs for 2025/05/24Author name: jnazario Pulse modified: 2025-05-24 12:27:45.354000 Indicator created: 2025-05-24 12:27:46 Indicator role: None Indicator title: Indicator expiration: 2025-06-23 12:00:00
- Origin AS
- AS201814 - PL-SKYTECH-AS
- AS15440 - Baltneta
- BGP Prefix
- 194.180.48.0/24
- events
- []
- geo
- Bulgaria
- 🕑 Europe/Sofia
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 194.180.48.0 - 194.180.49.255
- last_activity
- 2025-05-24 16:32:27.123000
- last_warden_event
- 2025-04-07 11:30:53
- rep
- 0.0
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 135, 139, 445, 3389
- Tags: self-signed
- CPEs: –
- ts_added
- 2025-03-14 09:41:11.215000
- ts_last_update
- 2025-07-11 09:41:20.291000
Warden event timeline
DShield event timeline
Presence on blacklists
OTX pulses