IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (323)
- 2026-09-03
-
- AnomalyTraffic (node.6a1878): 2
- ReconScanning (node.4dc198): 21
- ReconScanning (node.86eb21): 25
- 2026-08-31
-
- ReconScanning (node.368407): 21
- ReconScanning (node.f90c6b): 24
- 2026-08-30
-
- AnomalyTraffic (node.6a1878): 2
- ReconScanning (node.4dc198): 21
- ReconScanning (node.86eb21): 207
- DShield reports (IP summary, reports)
- 2026-09-01
- Number of reports: 47
- Distinct targets: 47
- 2026-09-02
- Number of reports: 47
- Distinct targets: 47
- 2026-09-04
- Number of reports: 1436
- Distinct targets: 1093
- 2026-09-05
- Number of reports: 274
- Distinct targets: 137
- 2026-09-06
- Number of reports: 128
- Distinct targets: 128
- 2026-09-07
- Number of reports: 128
- Distinct targets: 128
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 50 | src | scan |
- Origin AS
- AS213877 - u1host-as
- BGP Prefix
- 2.27.8.0/24
- geo
- United States
- 🕑 America/Chicago
- hostname
- vm1097326.hosted-by.u1host.com
- Address block ('inetnum' or 'NetRange' in whois database)
- 2.24.0.0 - 2.31.255.255
- last_activity
- 2026-09-03 08:23:09
- last_warden_event
- 2026-09-03 08:23:09
- rep
- 0.00012153941094772414
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 22, 443
- Tags: –
- CPEs: cpe:/a:openbsd:openssh:9.6p1, cpe:/o:canonical:ubuntu_linux
- ts_added
- 2026-08-30 09:33:16.143000
- ts_last_update
- 2026-09-20 09:33:21.252000
Warden event timeline
DShield event timeline
Presence on blacklists

