IP address


.000212.64.215.5bwater.jegte.biz
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
212.64.215.5 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2024-10-19 02:50:00.942000
Was present on blacklist at: 2024-10-01 02:50, 2024-10-02 02:50, 2024-10-03 02:50, 2024-10-04 02:50, 2024-10-05 02:50, 2024-10-06 02:50, 2024-10-07 02:50, 2024-10-08 02:50, 2024-10-09 02:50, 2024-10-10 02:50, 2024-10-11 02:50, 2024-10-12 02:50, 2024-10-13 02:50, 2024-10-14 02:50, 2024-10-15 02:50, 2024-10-17 02:50, 2024-10-18 02:50, 2024-10-19 02:50
AbuseIPDB
212.64.215.5 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2024-11-05 05:00:00.491000
Was present on blacklist at: 2024-10-01 04:00, 2024-10-02 04:00, 2024-10-03 04:00, 2024-10-04 04:00, 2024-10-05 04:00, 2024-10-06 04:00, 2024-10-07 04:00, 2024-10-08 04:00, 2024-10-09 04:00, 2024-10-10 04:00, 2024-10-11 04:00, 2024-10-12 04:00, 2024-10-13 04:00, 2024-10-14 04:00, 2024-10-15 04:00, 2024-10-17 04:00, 2024-10-18 04:00, 2024-10-20 04:00, 2024-10-26 04:00, 2024-10-27 05:00, 2024-10-28 05:00, 2024-10-29 05:00, 2024-10-30 05:00, 2024-10-31 05:00, 2024-11-01 05:00, 2024-11-02 05:00, 2024-11-03 05:00, 2024-11-04 05:00, 2024-11-05 05:00
Turris greylist
212.64.215.5 is listed on the Turris greylist blacklist.

Description: Greylist is the output of the Turris research project by CZ.NIC,<br>which collects data of malicious IPs.
Type of feed: primary (feed detail page)

Last checked at: 2024-11-05 22:15:00.209000
Was present on blacklist at: 2024-10-10 21:15, 2024-10-11 21:15, 2024-10-21 21:15, 2024-10-26 21:15, 2024-10-28 22:15, 2024-10-29 22:15, 2024-10-30 22:15, 2024-11-01 22:15, 2024-11-02 22:15, 2024-11-03 22:15, 2024-11-05 22:15
Warden events (5193)
2024-10-17
ReconScanning (node.368407): 125
ReconScanning (node.4dc198): 122
2024-10-16
ReconScanning (node.4dc198): 28
ReconScanning (node.368407): 27
2024-10-15
ReconScanning (node.4dc198): 6
ReconScanning (node.368407): 5
2024-10-14
ReconScanning (node.368407): 246
ReconScanning (node.4dc198): 244
2024-10-13
ReconScanning (node.4dc198): 142
ReconScanning (node.368407): 146
2024-10-12
ReconScanning (node.368407): 79
ReconScanning (node.4dc198): 16
2024-10-11
ReconScanning (node.368407): 26
ReconScanning (node.4dc198): 4
2024-10-10
ReconScanning (node.368407): 233
ReconScanning (node.4dc198): 36
2024-10-09
ReconScanning (node.368407): 279
ReconScanning (node.4dc198): 275
2024-10-08
ReconScanning (node.4dc198): 251
ReconScanning (node.368407): 255
2024-10-07
ReconScanning (node.368407): 188
ReconScanning (node.4dc198): 189
2024-10-06
ReconScanning (node.4dc198): 205
ReconScanning (node.368407): 207
2024-10-05
ReconScanning (node.4dc198): 239
ReconScanning (node.368407): 251
ReconScanning (node.cfb4f7): 1
2024-10-04
ReconScanning (node.368407): 210
ReconScanning (node.4dc198): 210
2024-10-03
ReconScanning (node.368407): 139
ReconScanning (node.4dc198): 49
2024-10-02
ReconScanning (node.368407): 216
ReconScanning (node.4dc198): 96
2024-10-01
ReconScanning (node.4dc198): 154
ReconScanning (node.368407): 154
2024-09-30
ReconScanning (node.ce2b59): 10
ReconScanning (node.4dc198): 54
ReconScanning (node.368407): 76
DShield reports (IP summary, reports)
2024-09-30
Number of reports: 1628
Distinct targets: 358
2024-10-01
Number of reports: 4738
Distinct targets: 400
2024-10-02
Number of reports: 1695
Distinct targets: 340
2024-10-03
Number of reports: 1132
Distinct targets: 286
2024-10-04
Number of reports: 1291
Distinct targets: 302
2024-10-05
Number of reports: 1526
Distinct targets: 296
2024-10-06
Number of reports: 1427
Distinct targets: 299
2024-10-07
Number of reports: 1368
Distinct targets: 298
2024-10-08
Number of reports: 1499
Distinct targets: 317
2024-10-09
Number of reports: 1746
Distinct targets: 372
2024-10-10
Number of reports: 1472
Distinct targets: 331
2024-10-11
Number of reports: 224
Distinct targets: 77
2024-10-12
Number of reports: 494
Distinct targets: 184
2024-10-13
Number of reports: 1074
Distinct targets: 297
2024-10-14
Number of reports: 1371
Distinct targets: 316
2024-10-15
Number of reports: 51
Distinct targets: 17
2024-10-16
Number of reports: 213
Distinct targets: 88
2024-10-17
Number of reports: 1006
Distinct targets: 345
2024-10-19
Number of reports: 4813
Distinct targets: 3885
2024-10-20
Number of reports: 1104
Distinct targets: 852
2024-10-25
Number of reports: 4047
Distinct targets: 3142
2024-10-26
Number of reports: 3572
Distinct targets: 2581
2024-10-27
Number of reports: 2084
Distinct targets: 1618
2024-10-28
Number of reports: 3838
Distinct targets: 2881
2024-10-29
Number of reports: 2634
Distinct targets: 2015
2024-10-30
Number of reports: 1727
Distinct targets: 1315
2024-10-31
Number of reports: 2344
Distinct targets: 1844
2024-11-01
Number of reports: 2470
Distinct targets: 1896
2024-11-02
Number of reports: 2478
Distinct targets: 2006
2024-11-03
Number of reports: 2134
Distinct targets: 1786
2024-11-04
Number of reports: 2142
Distinct targets: 1769
OTX pulses
[606d75c11c08ff94089a9430] 2021-04-07 09:05:05.353000 | Georgs Honeypot
Author name:georgengelmann
Pulse modified:2024-11-05 19:02:30.654000
Indicator created:2024-10-29 11:52:03
Indicator role:trojan
Indicator title:Death, Trojan from bwater.jegte.biz port 43529
Indicator expiration:2024-11-28 11:00:00
Origin AS
AS197450 - SUNUCUN
BGP Prefix
212.64.215.0/24
geo
Turkey, Istanbul
🕑 Europe/Istanbul
hostname
bwater.jegte.biz
Address block ('inetnum' or 'NetRange' in whois database)
212.64.192.0 - 212.64.223.255
last_activity
2024-11-05 20:45:25.260000
last_warden_event
2024-10-17 11:53:35
rep
0.0
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags: scanner
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.2p1
ts_added
2024-09-30 15:45:54.239000
ts_last_update
2024-11-05 22:16:07.128000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses