IP address


.052198.27.76.6tesa.myscriptcase.com
Shodan(more info)
Passive DNS
Tags: Malware
Warden events (335)
2024-12-19
Malware (node.5870ac): 335
DShield reports (IP summary, reports)
2024-12-19
Number of reports: 104
Distinct targets: 52
Origin AS
AS16276 - OVH
BGP Prefix
198.27.64.0/18
geo
Canada
🕑 America/Toronto
hostname
tesa.myscriptcase.com
Address block ('inetnum' or 'NetRange' in whois database)
198.27.64.0 - 198.27.127.255
last_activity
2024-12-19 10:03:57.489000
last_warden_event
2024-12-19 10:03:57.489000
rep
0.05238095238095238
reserved_range
0
Shodan's InternetDB
Open ports: 22, 53, 80, 110, 143, 443, 465, 587, 993, 2079, 2082, 2083, 2086, 2087, 3050, 3306, 8080, 8443, 10050
Tags: starttls, database
CPEs: cpe:/a:f5:nginx, cpe:/a:cpanel:cpanel, cpe:/a:cpanel:whm, cpe:/a:mariadb:mariadb:10.11.8-MariaDB, cpe:/a:exim:exim:4.98, cpe:/a:openbsd:openssh:8.0, cpe:/a:apache:http_server
ts_added
2024-12-19 09:59:42.958000
ts_last_update
2024-12-22 09:59:50.383000

Warden event timeline

DShield event timeline