IP address


.543195.182.16.52
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
AbuseIPDB
195.182.16.52 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-08-08 04:00:00.622000
Was present on blacklist at: 2026-08-04 04:00, 2026-08-05 04:00, 2026-08-07 04:00, 2026-08-08 04:00
Echelon directory traversal
195.182.16.52 is listed on the Echelon directory traversal blacklist.

Description: Path traversal attack attempting to access restricted files
Type of feed: primary (feed detail page)

Last checked at: 2026-08-08 09:15:00.287000
Was present on blacklist at: 2026-08-04 09:15, 2026-08-05 09:15, 2026-08-06 09:15, 2026-08-07 09:15, 2026-08-08 09:15
Echelon TLS/SSL crawler
195.182.16.52 is listed on the Echelon TLS/SSL crawler blacklist.

Description: TLS/SSL connection fingerprinting detected via Suricata
Type of feed: primary (feed detail page)

Last checked at: 2026-08-08 09:40:00.391000
Was present on blacklist at: 2026-08-04 09:40, 2026-08-05 09:40, 2026-08-06 09:40, 2026-08-07 09:40, 2026-08-08 09:40
Echelon web crawler
195.182.16.52 is listed on the Echelon web crawler blacklist.

Description: HTTP web crawling activity detected on web honeypots
Type of feed: primary (feed detail page)

Last checked at: 2026-08-08 09:50:00.318000
Was present on blacklist at: 2026-08-04 09:50, 2026-08-05 09:50, 2026-08-06 09:50, 2026-08-07 09:50, 2026-08-08 09:50
DShield Block
195.182.16.52 is listed on the DShield Block blacklist.

Description: Recommended Block List by DShield.org. It summarizes the top 20 attacking<br>class C (/24) subnets over the last three days.
Type of feed: secondary (feed detail page)

Last checked at: 2026-08-08 04:50:00
Was present on blacklist at: 2026-08-06 04:50, 2026-08-07 04:50, 2026-08-08 04:50

Threat categories

TLRoleCategoryDetails
70 src scan port: 80
31 src
25 src exploit protocol: http

Warden events (13)
2026-08-06
AnomalyTraffic (node.6a1878): 5
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 1
ReconScanning (node.ce2b59): 1
2026-08-03
ReconScanning (node.ce2b59): 1
AnomalyTraffic (node.6a1878): 2
ReconScanning (node.4dc198): 1
ReconScanning (node.368407): 1
DShield reports (IP summary, reports)
2026-08-03
Number of reports: 61
Distinct targets: 36
2026-08-04
Number of reports: 593
Distinct targets: 386
2026-08-05
Number of reports: 616
Distinct targets: 425
2026-08-06
Number of reports: 444
Distinct targets: 320
2026-08-07
Number of reports: 444
Distinct targets: 320
Origin AS
AS206264 - AMARUTU-TECHNOLOGY
BGP Prefix
195.182.16.0/24
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
195.182.16.0 - 195.182.16.255
last_activity
2026-08-06 23:19:56
last_warden_event
2026-08-06 23:19:56
rep
0.5432944806798239
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80
Tags:
CPEs: cpe:/a:openbsd:openssh:9.9
ts_added
2026-08-03 06:47:36.632000
ts_last_update
2026-08-08 09:50:47.275000

Warden event timeline

DShield event timeline

Presence on blacklists