IP address


.188154.59.103.16scan-16.tttx.net
Shodan(more info)
Passive DNS
Tags: Residential proxy
IP blacklists
blocklist.de SSH
154.59.103.16 was recently listed on the blocklist.de SSH blacklist, but currently it is not.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2026-09-18 22:05:00.170000
Was present on blacklist at: 2026-09-17 04:05, 2026-09-17 10:05, 2026-09-17 16:05, 2026-09-17 22:05, 2026-09-18 04:05, 2026-09-18 10:05, 2026-09-18 16:05, 2026-09-18 22:05
CI Army
154.59.103.16 was recently listed on the CI Army blacklist, but currently it is not.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2026-09-25 02:50:00.843000
Was present on blacklist at: 2026-09-20 02:50, 2026-09-21 02:50, 2026-09-22 02:50, 2026-09-23 02:50, 2026-09-25 02:50
AbuseIPDB
154.59.103.16 was recently listed on the AbuseIPDB blacklist, but currently it is not.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-09-28 04:00:00.712000
Was present on blacklist at: 2026-09-22 04:00, 2026-09-23 04:00, 2026-09-26 04:00, 2026-09-27 04:00, 2026-09-28 04:00
UCEPROTECT L1
154.59.103.16 is listed on the UCEPROTECT L1 blacklist.

Description: UCEPROTECT-NETWORK list of spam IPs.
Type of feed: primary (feed detail page)

Last checked at: 2026-10-02 15:45:00.643000
Was present on blacklist at: 2026-09-28 23:45, 2026-09-29 07:45, 2026-09-29 15:45, 2026-09-29 23:45, 2026-09-30 07:45, 2026-09-30 15:45, 2026-09-30 23:45, 2026-10-01 07:45, 2026-10-01 15:45, 2026-10-01 23:45, 2026-10-02 07:45, 2026-10-02 15:45

Threat categories

TLRoleCategoryDetails
59 src scan
38 src —
25 src login protocol: ftp
port: 21

Warden events (22)
2026-09-28
IntrusionUserCompromise (node.cfb4f7): 1
2026-09-27
IntrusionUserCompromise (node.cfb4f7): 1
2026-09-26
ReconScanning (node.f90c6b): 1
2026-09-25
ReconScanning (node.368407): 2
ReconScanning (node.f90c6b): 1
2026-09-24
AnomalyTraffic (node.6a1878): 1
2026-09-23
AnomalyTraffic (node.6a1878): 1
2026-09-21
AnomalyTraffic (node.6a1878): 1
2026-09-20
AnomalyTraffic (node.6a1878): 1
2026-09-19
ReconScanning (node.f90c6b): 1
ReconScanning (node.368407): 1
AnomalyTraffic (node.6a1878): 4
2026-09-16
ReconScanning (node.368407): 1
ReconScanning (node.f90c6b): 1
2026-09-15
AnomalyTraffic (node.ce2b59): 1
ReconScanning (node.ce2b59): 1
2026-09-06
ReconScanning (node.86eb21): 1
AvailabilityDoS (node.4dc198): 1
DShield reports (IP summary, reports)
2026-09-16
Number of reports: 136
Distinct targets: 136
2026-09-17
Number of reports: 418
Distinct targets: 298
2026-09-18
Number of reports: 335
Distinct targets: 225
2026-09-19
Number of reports: 335
Distinct targets: 225
2026-09-20
Number of reports: 296
Distinct targets: 233
2026-09-21
Number of reports: 293
Distinct targets: 231
2026-09-22
Number of reports: 173
Distinct targets: 168
2026-09-23
Number of reports: 406
Distinct targets: 286
2026-09-24
Number of reports: 521
Distinct targets: 461
2026-09-25
Number of reports: 521
Distinct targets: 461
2026-09-26
Number of reports: 166
Distinct targets: 113
2026-09-27
Number of reports: 166
Distinct targets: 113
Residential proxy info (data provided by Layer3 Intel)
Last seen: 2026-09-26 04:25:14}
Percent days seen: 13 %
Networks: DECODO, KOOKEY, PROXY-SELLER, PURAROUTE
Details: https://layer3intel.com/context/154.59.103.16
Origin AS
AS174 - COGENT-174
BGP Prefix
154.59.103.0/24
geo
United States, Los Angeles
🕑 America/Los_Angeles
hostname
scan-16.tttx.net
Address block ('inetnum' or 'NetRange' in whois database)
154.59.0.0 - 154.59.255.255
last_activity
2026-09-28 02:25:46
last_warden_event
2026-09-28 02:25:46
rep
0.18775413105612615
reserved_range
0
ts_added
2026-09-07 12:06:50.321000
ts_last_update
2026-10-02 15:52:50.452000

Warden event timeline

DShield event timeline

Presence on blacklists