IP address


--31.220.40.22nl7.nlkoddos.com
Shodan(more info)
Passive DNS
Tags:
IP blacklists
FireHOL anonymizers
31.220.40.22 is listed on the FireHOL anonymizers blacklist.

Description: List of anonymizing IPs, aggregated from multiple lists by FireHOL.
Type of feed: secondary (feed detail page)

Last checked at: 2025-09-18 00:05:08
Was present on blacklist at: 2025-09-05 00:05, 2025-09-06 00:05, 2025-09-07 00:05, 2025-09-08 00:05, 2025-09-09 00:05, 2025-09-10 00:05, 2025-09-11 00:05, 2025-09-12 00:05, 2025-09-13 00:05, 2025-09-14 00:05, 2025-09-15 00:05, 2025-09-16 00:05, 2025-09-17 00:05, 2025-09-18 00:05
OTX pulses
[68b9d266a57b122998115dc6] 2025-09-04 17:54:46.837000 | Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
Author name:AlienVault
Pulse modified:2025-09-10 18:58:13.114000
Indicator created:2025-09-04 17:54:49
Indicator role:None
Indicator title:
Indicator expiration:2025-10-04 17:00:00
Origin AS
AS206264 - AMARUTU-TECHNOLOGY
BGP Prefix
31.220.40.0/23
geo
Netherlands
🕑 Europe/Amsterdam
hostname
nl7.nlkoddos.com
Address block ('inetnum' or 'NetRange' in whois database)
31.220.40.0 - 31.220.47.255
last_activity
2025-09-10 20:08:28.107000
reserved_range
0
Shodan's InternetDB
Open ports: 21, 53, 80, 110, 143, 443, 465, 587, 993, 995, 2077, 2082, 2083, 2086, 2087, 2095, 2096, 52230
Tags: starttls
CPEs: cpe:/a:exim:exim:4.96.2, cpe:/a:pureftpd:pure-ftpd
ts_added
2025-09-05 00:01:36.403000
ts_last_update
2025-09-18 00:01:42.158000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses