IP address


--159.223.239.215
Shodan(more info)
Passive DNS
Tags:
IP blacklists
blocklist.de SSH
159.223.239.215 is listed on the blocklist.de SSH blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing SSH attacks.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-08 23:05:05.160000
Was present on blacklist at: 2025-12-08 23:05
DataPlane SSH login
159.223.239.215 is listed on the DataPlane SSH login blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs trying<br>an unsolicited login to a host using SSH password authentication.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-15 19:10:06.145000
Was present on blacklist at: 2025-12-09 03:10, 2025-12-09 07:10, 2025-12-09 15:10, 2025-12-09 19:10, 2025-12-10 03:10, 2025-12-10 07:10, 2025-12-10 15:10, 2025-12-10 19:10, 2025-12-11 03:10, 2025-12-11 07:10, 2025-12-11 15:10, 2025-12-11 19:10, 2025-12-12 03:10, 2025-12-12 07:10, 2025-12-12 15:10, 2025-12-12 19:10, 2025-12-13 03:10, 2025-12-13 07:10, 2025-12-13 15:10, 2025-12-13 19:10, 2025-12-14 03:10, 2025-12-14 07:10, 2025-12-14 15:10, 2025-12-14 19:10, 2025-12-15 03:10, 2025-12-15 07:10, 2025-12-15 15:10, 2025-12-15 19:10
blocklist.de web-login
159.223.239.215 is listed on the blocklist.de web-login blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs that attacks Joomla, Wordpress and<br>other Web-Logins with Brute-Force Logins.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-10 23:05:00.449000
Was present on blacklist at: 2025-12-09 05:05, 2025-12-09 11:05, 2025-12-09 17:05, 2025-12-09 23:05, 2025-12-10 05:05, 2025-12-10 11:05, 2025-12-10 17:05, 2025-12-10 23:05
blocklist.de Apache
159.223.239.215 is listed on the blocklist.de Apache blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing attacks on the service<br>Apache, Apache-DDOS, RFI-Attacks.
Type of feed: primary (feed detail page)

Last checked at: 2025-12-10 23:05:00.594000
Was present on blacklist at: 2025-12-09 05:05, 2025-12-09 11:05, 2025-12-09 17:05, 2025-12-09 23:05, 2025-12-10 05:05, 2025-12-10 11:05, 2025-12-10 17:05, 2025-12-10 23:05
DShield reports (IP summary, reports)
2025-12-08
Number of reports: 795
Distinct targets: 7
Origin AS
AS14061 - DIGITALOCEAN-ASN
BGP Prefix
159.223.224.0/20
geo
Netherlands, Amsterdam
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
159.223.0.0 - 159.223.255.255
reserved_range
0
Shodan's InternetDB
Open ports: 22, 24, 25, 79, 102, 113, 443, 444, 445, 502, 513, 902, 1400, 1521, 1604, 1800, 1926, 1935, 2000, 2003, 2008, 2021, 2121, 2233, 2345, 2404, 2506, 3001, 3100, 3145, 3341, 3542, 4042, 4242, 4244, 4443, 5000, 5004, 5007, 5025, 5222, 5244, 5435, 5542, 5600, 5601, 5801, 5900, 5902, 5905, 6000, 6001, 6036, 6331, 7001, 7010, 7415, 8000, 8008, 8023, 8036, 8101, 8105, 8106, 8118, 8123, 8124, 8142, 8144, 8415, 8419, 8445, 8501, 8521, 8523, 8545, 8800, 8804, 8808, 8825, 9000, 9025, 9100, 9115, 9146, 9209, 9418, 9444, 9501, 9530, 9600, 9804, 9902, 9930, 9944, 9999, 10000, 10003, 10004, 10006, 10028, 10032, 10044, 10134, 10243, 10533, 11110, 11112, 11443
Tags: cloud
CPEs: cpe:/a:cloudflare:cloudflare, cpe:/a:openbsd:openssh:8.2p1, cpe:/o:canonical:ubuntu_linux
ts_added
2025-12-08 23:07:08.815000
ts_last_update
2025-12-20 23:07:11.492000

Warden event timeline

DShield event timeline

Presence on blacklists