IP address


.005138.68.79.143
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
CI Army
138.68.79.143 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-12-06 03:50:00.975000
Was present on blacklist at: 2025-12-03 03:50, 2025-12-04 03:50, 2025-12-05 03:50, 2025-12-06 03:50
Warden events (17)
2025-12-06
ReconScanning (node.9c1411): 6
2025-12-05
ReconScanning (node.9c1411): 5
2025-12-04
ReconScanning (node.9c1411): 3
2025-12-03
ReconScanning (node.9c1411): 3
Origin AS
AS14061 - DIGITALOCEAN-ASN
BGP Prefix
138.68.64.0/20
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
138.68.0.0 - 138.68.255.255
last_activity
2025-12-06 22:47:48
last_warden_event
2025-12-06 22:47:48
rep
0.0046875
reserved_range
0
Shodan's InternetDB
Open ports: 22, 23, 26, 66, 79, 80, 88, 100, 104, 110, 119, 400, 441, 442, 443, 700, 800, 888, 1443, 2000, 2030, 2101, 2443, 3141, 3500, 4000, 4433, 5010, 5229, 5240, 5609, 6036, 6440, 6633, 8008, 8080, 8129, 8142, 8440, 8441, 8800, 8840, 8842, 9017, 9028, 9042, 9242, 9300, 9916, 9930, 9999, 20107, 20202, 20208, 45001, 45006
Tags: cloud
CPEs: cpe:/a:python:python:3.9.19, cpe:/o:canonical:ubuntu_linux, cpe:/a:palletsprojects:flask:2.0.1, cpe:/a:openbsd:openssh:8.2p1
ts_added
2025-12-03 03:55:05.549000
ts_last_update
2025-12-19 03:55:10.707000

Warden event timeline

DShield event timeline

Presence on blacklists