IP address


.057159.203.20.137
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
Spamhaus XBL CBL
159.203.20.137 was recently listed on the Spamhaus XBL CBL blacklist, but currently it is not.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-09 16:03:50.183000
Was present on blacklist at: 2025-12-02 16:03
Warden events (11)
2025-12-07
ReconScanning (node.9c1411): 3
2025-12-05
ReconScanning (node.9c1411): 4
2025-12-04
ReconScanning (node.9c1411): 2
2025-12-02
ReconScanning (node.9c1411): 2
Origin AS
AS14061 - DIGITALOCEAN-ASN
BGP Prefix
159.203.16.0/20
geo
Canada, Toronto
🕑 America/Toronto
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
159.203.0.0 - 159.203.255.255
last_activity
2025-12-07 02:18:14
last_warden_event
2025-12-07 02:18:14
rep
0.05714285714285714
reserved_range
0
Shodan's InternetDB
Open ports: 21, 80, 104, 143, 465, 587, 1153, 1177, 1234, 1414, 1433, 1446, 1456, 1471, 1515, 1521, 1650, 1801, 1901, 1911, 1925, 1926, 1959, 1962, 1969, 1982, 2000, 2006, 2055, 2064, 2079, 2081, 2086, 2087, 2091, 2103, 2130, 2134, 2181, 2211, 2222, 2332, 2362, 2480, 2548, 2601, 2602, 2762, 3000, 3011, 3017, 3047, 3050, 3057, 3059, 3063, 3065, 3078, 3107, 3113, 3136, 3139, 3142, 3164, 3178, 3181, 3182, 3195, 3269, 3299, 3306, 3310, 3311, 3333, 3388, 3390, 3406, 3569, 3689, 3780, 3790, 3954, 4000, 4040, 4101, 4147, 4150, 4157, 4159, 4160, 4190, 4242, 4282, 4369, 4433, 4444, 4449, 4451, 4506, 4567, 4782, 4786, 4840, 4848, 4911, 5001, 5005, 5006, 5010, 5025, 5100, 5140, 5172, 5201, 5249, 5251, 5272, 5357, 5433, 5435, 5443, 5495, 5544, 5556, 5591, 5601, 5604, 5630, 5672, 5701, 5800, 5901, 5913, 5938, 5984, 6000, 6001, 6002, 6022, 6161, 6348, 6510, 6514, 6550, 6622, 6633, 6664, 6666, 6697, 6887, 6955, 7012, 7020, 7071, 7171, 7218, 7403, 7415, 7776, 7989, 7999, 8001, 8002, 8009, 8010, 8015, 8017, 8049, 8053, 8075, 8080, 8081, 8086, 8087, 8089, 8094, 8096, 8099, 8115, 8123, 8125, 8131, 8145, 8153, 8156, 8173, 8185, 8186, 8188, 8194, 8195, 8199, 8200, 8250, 8316, 8334, 8381, 8414, 8415, 8422, 8423, 8427, 8449, 8480, 8532, 8557, 8586, 8705, 8706, 8767, 8787, 8815, 8828, 8850, 8863, 8867, 8870, 8877, 8880, 8881, 8882, 8883, 8888, 8889, 8899, 8901, 8935, 9000, 9002, 9022, 9025, 9027, 9028, 9043, 9060, 9079, 9080, 9091, 9094, 9100, 9103, 9108, 9109, 9112, 9116, 9136, 9143, 9152, 9158, 9182, 9187, 9194, 9201, 9214, 9223, 9283, 9306, 9350, 9454, 9529, 9530, 9600, 9682, 9765, 9800, 9869, 9898, 9943, 9944, 9994, 9999, 10002, 10016, 10020, 10043, 10052, 10082, 10134, 10250, 10393, 10554, 10911, 11112, 11184, 11210, 11300, 11443, 11596, 12101, 12142, 12183, 12185, 12186, 12187, 12191, 12194, 12206, 12210, 12222, 12241, 12251, 12253, 12261, 12273, 12289, 12295, 12300, 12305, 12321, 12346, 12351, 12356, 12370, 12380, 12382, 12383, 12393, 12396, 12397, 12398, 12400, 12438, 12442, 12445, 12449, 12474, 12486, 12495, 12502, 12558, 12560, 12561, 12569, 12583, 13443, 14084, 14265, 14403, 14875, 14900, 14901, 14903, 15123, 16009, 16015, 16041, 16055, 16061, 16084, 16096, 16099, 16101, 16992, 17000, 17084, 17182, 18006, 18014, 18044, 18049, 18078, 18089, 18181, 18200, 18245, 19016, 19017, 19071, 19082, 19091, 20040, 20100, 20110, 20500, 20547, 20880, 21025, 21244, 21275, 21302, 21308, 21323, 21330, 21443, 22082, 22084, 22206, 22222, 22556, 22703, 24084, 24442, 25001, 27015, 28015, 28443, 28818, 29799, 29840, 30002, 30006, 30101, 30104, 32400, 32800, 35000, 35101, 37215, 37777, 38520, 40070, 41800, 42235, 44158, 44336, 44399, 44410, 44818, 45333, 45677, 45777, 47990, 49152, 49153, 49443, 50009, 50013, 50014, 50022, 50042, 50070, 50805, 50995, 51106, 51235, 52311, 53200, 55350, 55555, 57778, 58443, 60001, 60021, 60129, 63210, 63260
Tags: cloud, honeypot, self-signed, database
CPEs: cpe:/a:microsoft:sql_server:8.0.528.0, cpe:/a:wordpress:wordpress:2.8, cpe:/a:python:python:3.11, cpe:/a:apache:http_server:2.2.22, cpe:/a:apache:tomcat, cpe:/o:canonical:ubuntu_linux, cpe:/a:mysql:mysql, cpe:/a:exim:exim:4.97, cpe:/a:php:php
ts_added
2025-12-02 16:03:48.485000
ts_last_update
2025-12-15 16:03:50.505000

Warden event timeline

DShield event timeline

Presence on blacklists