IP address
Shodan(more info)

Passive DNS

- IP blacklists
- DShield reports (IP summary, reports)
- 2026-02-24
- Number of reports: 283
- Distinct targets: 194
- 2026-02-25
- Number of reports: 283
- Distinct targets: 194
- 2026-03-17
- Number of reports: 263
- Distinct targets: 197
- OTX pulses
-
[69970e37e69fb5d88853ad26] 2026-02-19 13:20:55.139000 | RDP honeypot logs for 2026/02/19
Author name: jnazario Pulse modified: 2026-02-19 13:20:55.139000 Indicator created: 2026-02-19 13:20:56 Indicator role: None Indicator title: Indicator expiration: 2026-03-21 13:00:00 [699dac91ee57c6e3c672ab66] 2026-02-24 13:50:09.849000 | RDP honeypot logs for 2026/02/24Author name: jnazario Pulse modified: 2026-02-24 13:50:09.849000 Indicator created: 2026-02-24 13:50:10 Indicator role: None Indicator title: Indicator expiration: 2026-03-26 13:00:00 [69a43d4d923eea074068c28a] 2026-03-01 13:21:17.380000 | RDP honeypot logs for 2026/03/01Author name: jnazario Pulse modified: 2026-03-01 13:21:17.380000 Indicator created: 2026-03-01 13:21:18 Indicator role: None Indicator title: Indicator expiration: 2026-03-31 13:00:00
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 50 | src | scan | |
| 41 | src | — |
- Origin AS
- AS215292 - Gravhosting
- BGP Prefix
- 81.161.239.0/24
- geo
- United States, Kansas City
- 🕑 America/Chicago
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 81.161.236.0 - 81.161.239.255
- last_activity
- 2026-03-01 16:39:58.510000
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 3389
- Tags: self-signed
- CPEs: –
- ts_added
- 2026-02-14 05:01:10.687000
- ts_last_update
- 2026-03-22 01:05:31.223000
Warden event timeline
DShield event timeline
Presence on blacklists
OTX pulses

