IP address


.000157.119.59.156
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Spamhaus SBL CSS
157.119.59.156 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-18 05:09:37.063000
Was present on blacklist at: 2025-09-25 05:08, 2025-10-02 05:09, 2025-10-09 05:19, 2025-10-16 05:06, 2025-10-23 05:09, 2025-10-30 05:10, 2025-11-06 05:10, 2025-11-20 05:08, 2025-12-18 05:09
Spamhaus XBL CBL
157.119.59.156 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-18 05:09:37.063000
Was present on blacklist at: 2025-09-25 05:08, 2025-10-02 05:09, 2025-10-09 05:19, 2025-10-16 05:06, 2025-10-23 05:09, 2025-10-30 05:10, 2025-11-06 05:10, 2025-11-20 05:08, 2025-12-04 05:15, 2025-12-11 05:09, 2025-12-18 05:09
Warden events (62)
2025-11-25
ReconScanning (node.368407): 1
2025-11-17
ReconScanning (node.368407): 2
ReconScanning (node.4dc198): 5
2025-11-14
ReconScanning (node.4dc198): 8
2025-11-11
ReconScanning (node.4dc198): 1
2025-11-06
ReconScanning (node.368407): 2
2025-11-04
ReconScanning (node.4dc198): 3
2025-11-03
ReconScanning (node.4dc198): 17
2025-10-08
ReconScanning (node.368407): 2
2025-10-06
ReconScanning (node.368407): 2
2025-10-03
ReconScanning (node.4dc198): 6
2025-10-01
ReconScanning (node.368407): 2
2025-09-30
IntrusionUserCompromise+AttemptExploit (node.2373ce): 1
ReconScanning (node.368407): 2
2025-09-29
ReconScanning (node.4dc198): 1
2025-09-22
ReconScanning (node.4dc198): 4
2025-09-19
ReconScanning (node.4dc198): 3
DShield reports (IP summary, reports)
2025-11-08
Number of reports: 10
Distinct targets: 3
2025-11-27
Number of reports: 15
Distinct targets: 15
Origin AS
AS9341 - ICONPLN-ID-AP
BGP Prefix
157.119.59.0/24
geo
Indonesia
🕑 Asia/Jakarta
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
157.119.56.0 - 157.119.59.255
last_activity
2025-11-25 05:25:43
last_warden_event
2025-11-25 05:25:43
rep
0.0
reserved_range
0
Shodan's InternetDB
Open ports: 161, 1701, 1723, 2000, 8888
Tags: vpn
CPEs:
ts_added
2025-08-21 05:06:20.269000
ts_last_update
2025-12-18 05:09:37.170000

Warden event timeline

DShield event timeline

Presence on blacklists