IP address


.104172.104.143.187172-104-143-187.ip.linodeusercontent.com
Shodan(more info)
Passive DNS
Tags: Scanner IP in hostname
IP blacklists
CI Army
172.104.143.187 is listed on the CI Army blacklist.

Description: Collective Intelligence Network Security is a Threat Intelligence<br>database that provides scores for IPs. Source of unspecified malicious attacks<br>most of them will be active attackers/scanners
Type of feed: primary (feed detail page)

Last checked at: 2025-04-24 02:50:01.092000
Was present on blacklist at: 2025-04-22 02:50, 2025-04-23 02:50, 2025-04-24 02:50
Warden events (15)
2025-04-26
ReconScanning (node.f90c6b): 12
ReconScanning (node.86eb21): 1
2025-04-25
ReconScanning (node.f90c6b): 2
DShield reports (IP summary, reports)
2025-04-21
Number of reports: 96
Distinct targets: 73
2025-04-22
Number of reports: 253
Distinct targets: 210
Origin AS
AS63949 - LINODE-AP
BGP Prefix
172.104.128.0/19
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
172-104-143-187.ip.linodeusercontent.com
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
172.104.0.0 - 172.105.255.255
last_activity
2025-04-26 14:10:14
last_warden_event
2025-04-26 14:10:14
rep
0.10356270926339287
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80, 443, 5006, 5007, 5025, 5172, 5222, 5236, 5357, 5432, 5503, 5555, 5672, 5858, 5904, 5907, 5917, 5918, 5920, 5938, 5984, 5985, 6006, 6011, 6080, 6102, 6379, 6664, 6666, 6668, 6697, 6998, 7001, 7071, 7171, 7415, 7434, 7547, 7548, 7657, 7777, 8000, 8001, 8008, 8009, 8010, 8060, 8069, 8071, 8081, 8082, 8083, 8085, 8086, 8087, 8088, 8094, 8098, 8099, 8110, 8112, 8123, 8126, 8128, 8139, 8140, 8147, 8188, 8190, 8291, 8333, 8334, 8413, 8422, 8443, 8513, 8592, 8602, 8649, 8765, 8819, 8843, 8876, 8888, 8901, 9000, 9001, 9002, 9019, 9024, 9045, 9051, 9078, 9092, 9127, 9151, 9154, 9191, 9212, 9216, 9245, 9333, 9443, 9600, 9633, 9800, 9898, 9922, 9929, 9943, 9981, 9998, 9999, 10000, 10082, 10909, 10911, 10936, 11210, 11211, 11288, 11300, 12000, 12147, 12235, 12341, 12373, 12430, 12459, 12563, 12567, 12569, 13579, 14026, 14265, 14407
Tags: cloud
CPEs: cpe:/a:f5:nginx, cpe:/a:apache:http_server:2.4.41, cpe:/a:openbsd:openssh:8.0
ts_added
2025-04-22 02:58:37.406000
ts_last_update
2025-04-30 03:12:36.708000

Warden event timeline

DShield event timeline

Presence on blacklists