IP address


.507213.209.159.118
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
213.209.159.118 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-01-11 03:50:00.930000
Was present on blacklist at: 2026-01-02 03:50, 2026-01-03 03:50, 2026-01-04 03:50, 2026-01-05 03:50, 2026-01-06 03:50, 2026-01-07 03:50, 2026-01-08 03:50, 2026-01-09 03:50, 2026-01-10 03:50, 2026-01-11 03:50
DShield Block
213.209.159.118 was recently listed on the DShield Block blacklist, but currently it is not.

Description: Recommended Block List by DShield.org. It summarizes the top 20 attacking<br>class C (/24) subnets over the last three days.
Type of feed: secondary (feed detail page)

Last checked at: 2026-01-13 04:50:00
Was present on blacklist at: 2026-01-02 04:50, 2026-01-03 04:50, 2026-01-04 04:50, 2026-01-06 04:50, 2026-01-07 04:50
AbuseIPDB
213.209.159.118 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-01-09 05:00:00.743000
Was present on blacklist at: 2026-01-02 05:00, 2026-01-03 05:00, 2026-01-04 05:00, 2026-01-05 05:00, 2026-01-06 05:00, 2026-01-07 05:00, 2026-01-08 05:00, 2026-01-09 05:00
Warden events (4105)
2026-01-11
ReconScanning (node.9c1411): 26
2026-01-10
ReconScanning (node.9c1411): 84
2026-01-09
ReconScanning (node.9c1411): 88
2026-01-08
ReconScanning (node.4dc198): 203
ReconScanning (node.368407): 202
ReconScanning (node.9c1411): 91
2026-01-07
ReconScanning (node.368407): 285
ReconScanning (node.4dc198): 287
ReconScanning (node.9c1411): 89
2026-01-06
ReconScanning (node.4dc198): 240
ReconScanning (node.368407): 239
ReconScanning (node.9c1411): 72
2026-01-05
ReconScanning (node.368407): 232
ReconScanning (node.4dc198): 234
ReconScanning (node.9c1411): 42
2026-01-04
ReconScanning (node.4dc198): 169
ReconScanning (node.368407): 126
2026-01-03
ReconScanning (node.4dc198): 287
ReconScanning (node.368407): 160
2026-01-02
ReconScanning (node.4dc198): 283
ReconScanning (node.368407): 218
2026-01-01
ReconScanning (node.4dc198): 236
ReconScanning (node.368407): 212
DShield reports (IP summary, reports)
2026-01-01
Number of reports: 721
Distinct targets: 568
2026-01-02
Number of reports: 721
Distinct targets: 568
2026-01-03
Number of reports: 783
Distinct targets: 607
2026-01-04
Number of reports: 475
Distinct targets: 363
2026-01-05
Number of reports: 645
Distinct targets: 515
2026-01-06
Number of reports: 822
Distinct targets: 605
2026-01-08
Number of reports: 582
Distinct targets: 440
Origin AS
AS208137 - FPS12
BGP Prefix
213.209.159.0/24
geo
Germany
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
213.209.128.0 - 213.209.159.255
last_activity
2026-01-11 06:48:12
last_warden_event
2026-01-11 06:48:12
rep
0.5071428571428572
reserved_range
0
Shodan's InternetDB
Open ports: 8080
Tags:
CPEs:
ts_added
2026-01-01 04:20:07.650000
ts_last_update
2026-01-13 04:20:10.154000

Warden event timeline

DShield event timeline

Presence on blacklists