IP address


--104.238.61.144nordns.crowncloud.net
Shodan(more info)
Passive DNS
Tags:
IP blacklists
FireHOL anonymizers
104.238.61.144 is listed on the FireHOL anonymizers blacklist.

Description: List of anonymizing IPs, aggregated from multiple lists by FireHOL.
Type of feed: secondary (feed detail page)

Last checked at: 2025-04-30 12:05:08
Was present on blacklist at: 2025-02-13 12:11, 2025-02-14 12:08, 2025-02-15 12:09, 2025-02-16 12:10, 2025-02-17 12:09, 2025-02-18 12:08, 2025-02-19 12:08, 2025-02-20 12:11, 2025-02-21 12:10, 2025-02-22 12:11, 2025-02-23 12:09, 2025-02-24 12:10, 2025-02-25 12:09, 2025-02-26 12:08, 2025-02-27 12:08, 2025-02-28 12:11, 2025-03-01 12:09, 2025-03-02 12:12, 2025-03-03 12:11, 2025-03-04 12:11, 2025-03-06 12:08, 2025-03-07 12:08, 2025-03-08 12:07, 2025-03-09 12:09, 2025-03-10 12:10, 2025-03-11 12:09, 2025-03-12 12:09, 2025-03-13 12:09, 2025-03-14 12:09, 2025-03-15 12:08, 2025-03-16 12:08, 2025-03-17 12:11, 2025-03-18 12:08, 2025-03-19 12:09, 2025-03-20 12:10, 2025-03-21 12:09, 2025-03-22 12:08, 2025-03-23 12:08, 2025-03-24 12:10, 2025-03-25 12:08, 2025-03-26 12:10, 2025-03-27 12:08, 2025-03-28 12:09, 2025-03-29 12:09, 2025-03-30 12:10, 2025-03-31 12:09, 2025-04-01 12:10, 2025-04-02 12:08, 2025-04-03 12:08, 2025-04-04 12:09, 2025-04-05 12:09, 2025-04-06 12:09, 2025-04-07 12:09, 2025-04-08 12:07, 2025-04-09 12:10, 2025-04-10 12:08, 2025-04-11 12:10, 2025-04-12 12:12, 2025-04-13 12:11, 2025-04-14 12:13, 2025-04-15 12:12, 2025-04-16 12:10, 2025-04-17 12:11, 2025-04-18 12:09, 2025-04-19 12:08, 2025-04-20 12:05, 2025-04-21 12:05, 2025-04-22 12:05, 2025-04-23 12:05, 2025-04-24 12:05, 2025-04-25 12:05, 2025-04-26 12:05, 2025-04-27 12:05, 2025-04-28 12:05, 2025-04-29 12:05, 2025-04-30 12:05
OTX pulses
[67adb578e5a854366958749c] 2025-02-13 09:03:52.184000 | Tracking Pyramid C2: Identifying Post-Exploitation Servers in Hunt
Author name:AlienVault
Pulse modified:2025-02-13 09:42:43.385000
Indicator created:2025-02-13 09:03:52
Indicator role:None
Indicator title:
Indicator expiration:2025-03-15 09:00:00
[67d40207691067461210a612] 2025-03-14 10:16:39.016000 | SocGholish's Intrusion Techniques Facilitate Distribution of RansomHub Ransomware
Author name:AlienVault
Pulse modified:2025-03-14 19:09:15.733000
Indicator created:2025-03-14 10:16:40
Indicator role:None
Indicator title:
Indicator expiration:2025-04-13 10:00:00
Origin AS
AS8100 - ASN-QUADRANET-GLOBAL
BGP Prefix
104.238.61.0/24
geo
United States, Los Angeles
🕑 America/Los_Angeles
hostname
nordns.crowncloud.net
Address block ('inetnum' or 'NetRange' in whois database)
104.238.32.0 - 104.238.63.255
last_activity
2025-03-14 20:35:17.592000
reserved_range
0
Shodan's InternetDB
Open ports: 22, 443, 554, 771, 8000
Tags:
CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.9p1
ts_added
2025-02-13 12:35:10.129000
ts_last_update
2025-04-30 12:35:20.226000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses