IP address


.00138.244.205.244
Shodan(more info)
Passive DNS
Tags:

Threat categories

TLRoleCategoryDetails
No threat category tags assigned

OTX pulses
[6a87ffab05b89766cd6c1700] 2026-08-21 07:35:07.627000 | Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants
Author name:AlienVault
Pulse modified:2026-08-21 08:00:46.940000
Indicator created:2026-08-21 07:35:08
Indicator role:None
Indicator title:
Indicator expiration:2026-09-20 07:00:00
[6a7b3ea2ac324259cbd21dc6] 2026-08-11 15:24:17.965000 | PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
Author name:AlienVault
Pulse modified:2026-08-11 15:39:30.597000
Indicator created:2026-08-11 15:24:18
Indicator role:None
Indicator title:
Indicator expiration:2026-09-10 15:00:00
Origin AS
AS58061 - SCALAXY-AS
BGP Prefix
38.244.205.0/24
geo
Finland, Helsinki
🕑 Europe/Helsinki
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
38.0.0.0 - 38.255.255.255
last_activity
2026-08-29 18:12:41.426000
rep
0.0011135435415386974
reserved_range
0
Shodan's InternetDB
Open ports: 22
Tags:
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.9p1
ts_added
2026-08-29 18:11:49.615000
ts_last_update
2026-09-16 18:11:51.637000

Warden event timeline

DShield event timeline

OTX pulses