IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (5)
- 2026-06-04
-
- AttemptLogin (node.ce2b59): 3
- 2026-06-03
-
- AttemptLogin (node.ce2b59): 2
- DShield reports (IP summary, reports)
- 2026-05-30
- Number of reports: 26
- Distinct targets: 3
Threat categories
| TL | Role | Category | Details |
|---|---|---|---|
| 69 | src | login | protocol: ssh port: 22 |
| 50 | src | scan |
- Origin AS
- AS26609 - LACNIC-26592
- BGP Prefix
- 189.8.0.0/20
- geo
- Brazil, Franco da Rocha
- 🕑 America/Sao_Paulo
- hostname
- 118-5-8-189.univ.com.br
- hostname_class
- ['ip_in_hostname']
- Address block ('inetnum' or 'NetRange' in whois database)
- 189.8.0.0 - 189.8.63.255
- last_activity
- 2026-06-04 06:56:43
- last_warden_event
- 2026-06-04 06:56:43
- rep
- 0.16922296389976532
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 91
- Tags: –
- CPEs: cpe:/a:perl:perl:5.34.1, cpe:/o:unix:unix, cpe:/a:php:php:8.2.12, cpe:/a:apache:mod_perl:2.0.12, cpe:/a:openssl:openssl:1.1.1w, cpe:/a:apache:http_server:2.4.58
- ts_added
- 2026-05-31 05:03:57.514000
- ts_last_update
- 2026-06-04 10:09:30.467000
Warden event timeline
DShield event timeline
Presence on blacklists

