IP address


.20780.251.153.178
Shodan(more info)
Passive DNS
Tags: Scanner

Threat categories

TLRoleCategoryDetails
60 src scan port: 23
43 src

Warden events (26)
2026-05-03
AnomalyTraffic (node.6a1878): 2
ReconScanning (node.ce2b59): 1
2026-05-01
ReconScanning (node.ce2b59): 8
AnomalyTraffic (node.6a1878): 7
2026-04-30
ReconScanning (node.ce2b59): 8
DShield reports (IP summary, reports)
2026-05-01
Number of reports: 674
Distinct targets: 5
2026-05-02
Number of reports: 429
Distinct targets: 5
2026-05-03
Number of reports: 429
Distinct targets: 5
2026-05-04
Number of reports: 15785
Distinct targets: 20
Origin AS
AS206264 - AMARUTU-TECHNOLOGY
BGP Prefix
80.251.153.0/24
geo
Netherlands, Amsterdam
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
80.251.152.0 - 80.251.153.255
last_activity
2026-05-03 22:11:21
last_warden_event
2026-05-03 22:11:21
rep
0.20725206647600444
reserved_range
0
Shodan's InternetDB
Open ports: 21, 22, 53, 110, 111, 143, 465, 587, 995, 2077, 2079, 2082, 2083, 2086, 2087, 3306
Tags: starttls, database, self-signed
CPEs: cpe:/a:cpanel:whm, cpe:/a:openbsd:openssh:8.0, cpe:/a:pureftpd:pure-ftpd, cpe:/a:mariadb:mariadb, cpe:/a:exim:exim:4.98.2, cpe:/a:cpanel:cpanel
ts_added
2026-04-30 18:53:27.736000
ts_last_update
2026-05-05 05:01:44.195000

Warden event timeline

DShield event timeline