IP address
Shodan(more info)

Passive DNS

- IP blacklists
- OTX pulses
-
[602bc528f447d628d41494f2] 2021-02-16 13:14:16.945000 | Ka's Honeypot visitors
Author name: Kapppppa Pulse modified: 2025-04-10 11:57:06.785000 Indicator created: 2025-03-11 15:41:34 Indicator role: bruteforce Indicator title: Telnet Login attempt Indicator expiration: 2025-04-10 15:00:00
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 120.26.0.0/16
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 120.24.0.0 - 120.27.255.255
- last_activity
- 2025-04-10 12:00:59.850000
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 17, 19, 21, 25, 37, 43, 49, 53, 70, 79, 80, 90, 102, 104, 111, 113, 119, 122, 135, 143, 175, 190, 264, 389, 427, 465, 503, 513, 548, 554, 666, 771, 789, 873, 880, 995, 1000, 1023, 1025, 1028, 1080, 1099, 1153, 1234, 1311, 1337, 1414, 1433, 1443, 1521, 1599, 1604, 1723, 1800, 1801, 1883, 1962, 2000, 2002, 2008, 2067, 2081, 2083, 2087, 2100, 2121, 2154, 2181, 2221, 2222, 2225, 2323, 2332, 2376, 2404, 2455, 2550, 2628, 2650, 2761, 2762, 3001, 3062, 3071, 3095, 3098, 3119, 3149, 3154, 3197, 3200, 3260, 3268, 3310, 3389, 3404, 3550, 3551, 3790, 4000, 4022, 4150, 4157, 4242, 4282, 4369, 4433, 4435, 4443, 4500, 4506, 4524, 4786, 4899, 4911, 4949, 4993, 5001, 5009, 5010, 5025, 5050, 5222, 5226, 5232, 5269, 5435, 5446, 5494, 5555, 5556, 5672, 5673, 5853, 5938, 5986, 6002, 6379, 6443, 6560, 6581, 6588, 6633, 6653, 6667, 6668, 7000, 7001, 7021, 7071, 7100, 7171, 7302, 7434, 7443, 7654, 7777, 7878, 7900, 8009, 8017, 8025, 8036, 8081, 8082, 8083, 8084, 8085, 8087, 8099, 8108, 8126, 8132, 8140, 8171, 8195, 8282, 8291, 8404, 8431, 8433, 8528, 8545, 8554, 8575, 8702, 8802, 8821, 8889, 8899, 9000, 9001, 9007, 9012, 9042, 9049, 9081, 9092, 9095, 9100, 9107, 9151, 9183, 9203, 9253, 9306, 9333, 9399, 9530, 9600, 9658, 9663, 9898, 9993, 9998, 9999, 10000, 10001, 10044, 10075, 10134, 10250, 10443, 10892, 10909, 11000, 11065, 11112, 11180, 11210, 11211, 11288, 12000, 12016, 12165, 12227, 12249, 12251, 12270, 12347, 12358, 12441, 12442, 12536, 14147, 15084, 16007, 16035, 16072, 16402, 16993, 18025, 18065, 18071, 18080, 18081, 18084, 18112, 18245, 19000, 19082, 20256, 20547, 20800, 20880, 20894, 21235, 21239, 21240, 21256, 21257, 21265, 21291, 21318, 21357, 21379, 22556, 24245, 25001, 25565, 26656, 27015, 27036, 28015, 28080, 30002, 30017, 30322, 30422, 30444, 30822, 31122, 31222, 31322, 31337, 32122, 32222, 32522, 32764, 32922, 33022, 33060, 33222, 33522, 34122, 34222, 34722, 35000, 35022, 35100, 35222, 35422, 35722, 36022, 36122, 36422, 37122, 37222, 37777, 38722, 39022, 39122, 39822, 40001, 40222, 40822, 41222, 41422, 41443, 41800, 41922, 42322, 42422, 42622, 42722, 44399, 44422, 44818, 45222, 45722, 45822, 46022, 46222, 46443, 46722, 46822, 46922, 47022, 47080, 47222, 47322, 47990, 48022, 48222, 48922, 50000, 50050, 50100, 50522, 50822, 51106, 51235, 51522, 51722, 51822, 51922, 52222, 52322, 52622, 53222, 53422, 54122, 54138, 54222, 54622, 55000, 55122, 55222, 55422, 55443, 55522, 55554, 55622, 55822, 55922, 56122, 56322, 56822, 56922, 57322, 57622, 57922, 58722, 58922, 59322, 60122, 63210, 63256, 63260
- Tags: eol-product, honeypot, proxy
- CPEs: cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:7.9, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:microsoft:qotd::::en, cpe:/a:openbsd:openssh:7.4, cpe:/h:dlink:dls-2750u, cpe:/a:openbsd:openssh:X.X, cpe:/a:apache:dubbo, cpe:/a:f5:nginx, cpe:/o:microsoft:windows, cpe:/a:openbsd:openssh:7.5, cpe:/a:openbsd:openssh:5.3, cpe:/a:f5:nginx:1.22.1, cpe:/a:openbsd:openssh:7.2p2, cpe:/o:hp:hp-ux, cpe:/a:eset:nod32_antivirus:99
- ts_added
- 2025-03-05 20:00:34.617000
- ts_last_update
- 2025-05-06 20:00:40.265000
Warden event timeline
DShield event timeline
Presence on blacklists
OTX pulses