IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (589)
- 2025-05-07
-
- IntrusionUserCompromise (node.cfb4f7): 12
- 2025-05-06
-
- ReconScanning (node.4dc198): 143
- IntrusionUserCompromise (node.cfb4f7): 296
- 2025-05-05
-
- ReconScanning (node.4dc198): 71
- IntrusionUserCompromise (node.cfb4f7): 67
- DShield reports (IP summary, reports)
- 2025-05-05
- Number of reports: 138
- Distinct targets: 63
- 2025-05-06
- Number of reports: 271
- Distinct targets: 149
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 118.31.0.0/17
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 118.31.0.0 - 118.31.255.255
- last_activity
- 2025-05-07 00:13:31
- last_warden_event
- 2025-05-07 00:13:31
- rep
- 0.24522181919642855
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 13, 17, 19, 21, 22, 53, 70, 79, 100, 111, 131, 143, 175, 179, 195, 221, 264, 400, 427, 442, 447, 465, 503, 513, 593, 602, 646, 808, 811, 830, 853, 1023, 1025, 1026, 1153, 1200, 1234, 1337, 1364, 1414, 1433, 1454, 1515, 1554, 1599, 1723, 1800, 1801, 1953, 1978, 2000, 2002, 2059, 2087, 2095, 2107, 2154, 2181, 2222, 2323, 2332, 2345, 2363, 2404, 2626, 2628, 3001, 3050, 3079, 3085, 3108, 3116, 3118, 3123, 3260, 3310, 3503, 3548, 3780, 3790, 4000, 4101, 4321, 4447, 4499, 4786, 5009, 5025, 5201, 5222, 5256, 5444, 5543, 5595, 5609, 5986, 5997, 6007, 6161, 6379, 6400, 6464, 6488, 6697, 7001, 7002, 7020, 7071, 7078, 7082, 7171, 7173, 7218, 7283, 7415, 7443, 7510, 7878, 8002, 8009, 8030, 8037, 8055, 8071, 8080, 8083, 8091, 8117, 8122, 8136, 8148, 8189, 8200, 8384, 8408, 8436, 8443, 8500, 8521, 8556, 8565, 8573, 8686, 8743, 8789, 8790, 8842, 8847, 8880, 8882, 9000, 9002, 9003, 9018, 9041, 9043, 9051, 9083, 9091, 9092, 9097, 9100, 9108, 9111, 9130, 9149, 9155, 9164, 9190, 9201, 9207, 9215, 9310, 9398, 9418, 9530, 9600, 9633, 9690, 9922, 9944, 9993, 10000, 10084, 10348, 10399, 10477, 10909, 10911, 11000, 11112, 11288, 12000, 12104, 12129, 12131, 12132, 12133, 12138, 12163, 12164, 12189, 12212, 12231, 12232, 12235, 12240, 12247, 12269, 12334, 12353, 12363, 12387, 12391, 12419, 12457, 12479, 12499, 12500, 12502, 12518, 12541, 12549, 12570, 12571, 12585, 14147, 14900, 16064, 16082, 16101, 16104, 16993, 18006, 18042, 18064, 18076, 18081, 18083, 18106, 18225, 18245, 18443, 18888, 19200, 19930, 20000, 20030, 20053, 20185, 20547, 20880, 20892, 21002, 21081, 21231, 21257, 21259, 21314, 21316, 21317, 21318, 21328, 21515, 21935, 22222, 22556, 23023, 24245, 25565, 27015, 27016, 28001, 28015, 30222, 31022, 31337, 31443, 31522, 32022, 32102, 32322, 32622, 32764, 33060, 35000, 37777, 41800, 42194, 44158, 44303, 44334, 44336, 44340, 44420, 45001, 45002, 45667, 48018, 49153, 49443, 50000, 50085, 51003, 51005, 52010, 54327, 54444, 54545, 55000, 58000, 60129, 61613, 61616, 62078, 63257, 63260, 64738
- Tags: honeypot, videogame, proxy
- CPEs: cpe:/a:openbsd:openssh:7.6p1, cpe:/a:apache:subversion, cpe:/a:microsoft:message_queuing, cpe:/a:openbsd:openssh:7.5, cpe:/a:f5:nginx, cpe:/a:openbsd:openssh:7.4, cpe:/a:apache:dubbo, cpe:/a:openbsd:openssh:5.3, cpe:/a:openbsd:openssh:6.6.1, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.0, cpe:/a:openbsd:openssh:8.2p1, cpe:/a:openbsd:openssh:7.9, cpe:/a:squid-cache:squid:3.5.20, cpe:/a:openbsd:openssh:7.2p2, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/o:microsoft:windows
- ts_added
- 2025-05-05 13:19:59.702000
- ts_last_update
- 2025-05-07 06:51:48.760000
Warden event timeline
DShield event timeline
Presence on blacklists