IP address
Shodan(more info)

Passive DNS

Tags:
- IP blacklists
- Echelon TLS/SSL crawler195.164.49.69 is listed on the Echelon TLS/SSL crawler blacklist.Echelon web crawler
Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:40:00.476000
Was present on blacklist at: 2026-08-20 09:40, 2026-08-21 09:40, 2026-08-22 09:40, 2026-08-23 09:40, 2026-08-24 09:40, 2026-08-25 09:40, 2026-08-26 09:40195.164.49.69 is listed on the Echelon web crawler blacklist.Echelon SSH bruteforce
Description: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:50:00.416000
Was present on blacklist at: 2026-08-20 09:50, 2026-08-21 09:50, 2026-08-22 09:50, 2026-08-23 09:50, 2026-08-24 09:50, 2026-08-25 09:50, 2026-08-26 09:50195.164.49.69 is listed on the Echelon SSH bruteforce blacklist.Echelon SSH connection attempt
Description: Multiple SSH authentication attempts detected
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:35:00.367000
Was present on blacklist at: 2026-08-22 09:35, 2026-08-23 09:35, 2026-08-24 09:35, 2026-08-25 09:35, 2026-08-26 09:35195.164.49.69 is listed on the Echelon SSH connection attempt blacklist.Echelon CGI script hunt
Description: SSH connection attempt detected on port 22 or 2222
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:35:00.464000
Was present on blacklist at: 2026-08-22 09:35, 2026-08-23 09:35, 2026-08-24 09:35, 2026-08-25 09:35, 2026-08-26 09:35195.164.49.69 is listed on the Echelon CGI script hunt blacklist.Echelon admin panel hunt
Description: Scanning for vulnerable CGI scripts
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:05:01.664000
Was present on blacklist at: 2026-08-23 09:05, 2026-08-24 09:05, 2026-08-25 09:05, 2026-08-26 09:05195.164.49.69 is listed on the Echelon admin panel hunt blacklist.Echelon CMS enumeration
Description: Scanning for administrative interfaces
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:05:01.628000
Was present on blacklist at: 2026-08-23 09:05, 2026-08-24 09:05, 2026-08-25 09:05, 2026-08-26 09:05195.164.49.69 is listed on the Echelon CMS enumeration blacklist.Echelon database admin hunt
Description: Content management system discovery and enumeration
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:05:04.484000
Was present on blacklist at: 2026-08-23 09:05, 2026-08-24 09:05, 2026-08-25 09:05, 2026-08-26 09:05195.164.49.69 is listed on the Echelon database admin hunt blacklist.Echelon config file hunt
Description: Scanning for database admin interfaces (phpMyAdmin, etc.)
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:10:00.284000
Was present on blacklist at: 2026-08-23 09:10, 2026-08-24 09:10, 2026-08-25 09:10, 2026-08-26 09:10195.164.49.69 is listed on the Echelon config file hunt blacklist.Echelon enterprise software probe
Description: Scanning for exposed configuration files
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:10:00.351000
Was present on blacklist at: 2026-08-23 09:10, 2026-08-24 09:10, 2026-08-25 09:10, 2026-08-26 09:10195.164.49.69 is listed on the Echelon enterprise software probe blacklist.Echelon directory traversal
Description: Probing for enterprise software (Confluence, Jenkins, etc.)
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:15:00.640000
Was present on blacklist at: 2026-08-23 09:15, 2026-08-24 09:15, 2026-08-25 09:15, 2026-08-26 09:15195.164.49.69 is listed on the Echelon directory traversal blacklist.Echelon file upload
Description: Path traversal attack attempting to access restricted files
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:15:00.403000
Was present on blacklist at: 2026-08-23 09:15, 2026-08-24 09:15, 2026-08-25 09:15, 2026-08-26 09:15195.164.49.69 is listed on the Echelon file upload blacklist.Echelon SQL injection
Description: Attempting to upload potentially malicious files
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:15:00.369000
Was present on blacklist at: 2026-08-23 09:15, 2026-08-24 09:15, 2026-08-25 09:15, 2026-08-26 09:15195.164.49.69 is listed on the Echelon SQL injection blacklist.Echelon router exploit
Description: None
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:30:00.433000
Was present on blacklist at: 2026-08-23 09:30, 2026-08-24 09:30, 2026-08-25 09:30, 2026-08-26 09:30195.164.49.69 is listed on the Echelon router exploit blacklist.Echelon web shell hunt
Description: Attempting router firmware exploits (Netgear, D-Link, etc.)
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:30:00.448000
Was present on blacklist at: 2026-08-23 09:30, 2026-08-24 09:30, 2026-08-25 09:30, 2026-08-26 09:30195.164.49.69 is listed on the Echelon web shell hunt blacklist.Echelon web vulnerability exploit
Description: Scanning for web shells (WSO, c99, r57, etc.)
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:50:00.273000
Was present on blacklist at: 2026-08-23 09:50, 2026-08-24 09:50, 2026-08-25 09:50, 2026-08-26 09:50195.164.49.69 is listed on the Echelon web vulnerability exploit blacklist.Echelon port scan
Description: Generic web application vulnerability exploit
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:55:00.375000
Was present on blacklist at: 2026-08-23 09:55, 2026-08-24 09:55, 2026-08-25 09:55, 2026-08-26 09:55195.164.49.69 is listed on the Echelon port scan blacklist.Echelon WordPress enumeration
Description: Scanning 5+ ports on target host
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:25:00.307000
Was present on blacklist at: 2026-08-24 09:25, 2026-08-25 09:25, 2026-08-26 09:25195.164.49.69 is listed on the Echelon WordPress enumeration blacklist.Echelon SolarWinds probe
Description: WordPress user and plugin enumeration
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:55:00.324000
Was present on blacklist at: 2026-08-25 09:55, 2026-08-26 09:55195.164.49.69 is listed on the Echelon SolarWinds probe blacklist.
Description: Probing for SolarWinds Orion endpoints
Type of feed: primary (feed detail page)
Last checked at: 2026-08-26 09:40:00.378000
Was present on blacklist at: 2026-08-26 09:40 - Warden events (3)
- 2026-08-23
-
- ReconScanning (node.c26a5f): 1
- 2026-08-22
-
- AttemptLogin (node.c26a5f): 1
- ReconScanning (node.c26a5f): 1
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 53 | src | scan | |
| 48 | src | exploit | protocol: http |
| 42 | src | login | protocol: ssh port: 22, 2222 |
- Origin AS
- AS8308 - NASK-COMMERCIAL
- BGP Prefix
- 195.164.0.0/16
- geo
- Poland
- 🕑 Europe/Warsaw
- hostname
- skanowanie.cert.pl
- Address block ('inetnum' or 'NetRange' in whois database)
- 195.164.0.0 - 195.164.255.255
- last_activity
- 2026-08-23 13:56:17.800000
- last_warden_event
- 2026-08-23 13:56:17.800000
- rep
- 0.9630478326621654
- reserved_range
- 0
- ts_added
- 2026-08-20 09:40:52.619000
- ts_last_update
- 2026-08-26 09:55:01.783000
Warden event timeline
DShield event timeline
Presence on blacklists

