IP address


.453212.164.112.28
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
DataPlane TELNET login
212.164.112.28 is listed on the DataPlane TELNET login blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs trying<br>an unsolicited login via TELNET password authentication.
Type of feed: primary (feed detail page)

Last checked at: 2025-11-14 11:10:02.514000
Was present on blacklist at: 2025-11-04 03:10, 2025-11-04 07:10, 2025-11-04 11:10, 2025-11-04 15:10, 2025-11-04 19:10, 2025-11-04 23:10, 2025-11-05 03:10, 2025-11-05 07:10, 2025-11-05 11:10, 2025-11-05 15:10, 2025-11-05 19:10, 2025-11-05 23:10, 2025-11-06 03:10, 2025-11-06 07:10, 2025-11-06 11:10, 2025-11-06 15:10, 2025-11-06 19:10, 2025-11-06 23:10, 2025-11-07 03:10, 2025-11-07 07:10, 2025-11-07 11:10, 2025-11-07 15:10, 2025-11-07 19:10, 2025-11-07 23:10, 2025-11-08 03:10, 2025-11-08 07:10, 2025-11-08 11:10, 2025-11-08 15:10, 2025-11-08 19:10, 2025-11-08 23:10, 2025-11-09 03:10, 2025-11-09 07:10, 2025-11-09 11:10, 2025-11-09 15:10, 2025-11-09 19:10, 2025-11-09 23:10, 2025-11-10 03:10, 2025-11-10 07:10, 2025-11-10 11:10, 2025-11-10 15:10, 2025-11-10 19:10, 2025-11-10 23:10, 2025-11-11 03:10, 2025-11-11 07:10, 2025-11-11 11:10, 2025-11-11 15:10, 2025-11-11 19:10, 2025-11-11 23:10, 2025-11-12 03:10, 2025-11-12 07:10, 2025-11-12 11:10, 2025-11-12 15:10, 2025-11-12 19:10, 2025-11-12 23:10, 2025-11-13 03:10, 2025-11-13 07:10, 2025-11-13 11:10, 2025-11-13 15:10, 2025-11-13 19:10, 2025-11-13 23:10, 2025-11-14 03:10, 2025-11-14 07:10, 2025-11-14 11:10
Turris greylist
212.164.112.28 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2025-11-13 22:15:00.167000
Was present on blacklist at: 2025-11-07 22:15, 2025-11-10 22:15, 2025-11-12 22:15, 2025-11-13 22:15
AbuseIPDB
212.164.112.28 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2025-11-14 05:00:00.694000
Was present on blacklist at: 2025-11-12 05:00, 2025-11-13 05:00, 2025-11-14 05:00
Warden events (66)
2025-11-14
ReconScanning (node.9c1411): 2
2025-11-13
ReconScanning (node.9c1411): 9
2025-11-12
ReconScanning (node.9c1411): 7
2025-11-11
ReconScanning (node.9c1411): 10
2025-11-10
ReconScanning (node.9c1411): 7
2025-11-09
ReconScanning (node.9c1411): 5
2025-11-08
ReconScanning (node.9c1411): 4
2025-11-07
ReconScanning (node.9c1411): 4
2025-11-06
ReconScanning (node.9c1411): 4
2025-11-05
ReconScanning (node.9c1411): 6
2025-11-04
ReconScanning (node.9c1411): 7
2025-11-03
ReconScanning (node.9c1411): 1
Origin AS
AS12389 - ROSTELECOM-AS
BGP Prefix
212.164.112.0/20
geo
Russia, Novosibirsk
🕑 Asia/Novosibirsk
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
212.164.0.0 - 212.164.255.255
last_activity
2025-11-14 02:53:11
last_warden_event
2025-11-14 02:53:11
rep
0.4528041294642858
reserved_range
0
Shodan's InternetDB
Open ports: 80, 81, 83, 84, 85, 86, 88, 89
Tags:
CPEs:
ts_added
2025-11-03 22:20:04.622000
ts_last_update
2025-11-14 11:32:27.955000

Warden event timeline

DShield event timeline

Presence on blacklists