IP address


.031197.189.207.3
Shodan(more info)
Passive DNS
Tags: Scanner
Warden events (22)
2025-12-13
ReconScanning (node.86eb21): 2
2025-12-09
ReconScanning (node.86eb21): 2
2025-12-08
ReconScanning (node.86eb21): 1
2025-12-07
ReconScanning (node.86eb21): 1
2025-12-02
ReconScanning (node.86eb21): 2
2025-12-01
ReconScanning (node.86eb21): 2
2025-11-09
ReconScanning (node.86eb21): 1
2025-11-08
ReconScanning (node.86eb21): 1
2025-11-01
ReconScanning (node.86eb21): 1
2025-10-31
ReconScanning (node.86eb21): 1
2025-10-28
ReconScanning (node.86eb21): 1
2025-10-21
ReconScanning (node.86eb21): 1
2025-10-19
ReconScanning (node.86eb21): 1
2025-10-16
ReconScanning (node.86eb21): 1
2025-10-09
ReconScanning (node.86eb21): 1
2025-09-26
ReconScanning (node.86eb21): 1
2025-09-25
ReconScanning (node.86eb21): 1
2025-09-23
ReconScanning (node.86eb21): 1
DShield reports (IP summary, reports)
2025-09-25
Number of reports: 24
Distinct targets: 4
2025-10-15
Number of reports: 36
Distinct targets: 5
Origin AS
AS37153 - xneelo
BGP Prefix
197.189.192.0/19
geo
South Africa
🕑 Africa/Johannesburg
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
197.189.192.0 - 197.189.255.255
last_activity
2025-12-13 01:43:32
last_warden_event
2025-12-13 01:43:32
rep
0.03095238095238095
reserved_range
0
Shodan's InternetDB
Open ports: 11, 15, 22, 37, 70, 80, 88, 143, 449, 453, 503, 593, 771, 789, 801, 947, 1050, 1452, 1951, 1986, 2061, 2082, 2101, 2107, 2248, 2362, 2455, 2563, 2628, 3001, 3005, 3015, 3066, 3104, 3109, 3124, 3170, 3173, 3182, 3187, 3192, 3198, 3306, 3342, 3549, 3556, 4080, 4103, 4118, 4242, 4543, 4567, 4664, 4747, 4911, 5001, 5090, 5201, 5252, 5253, 5265, 5543, 5592, 5595, 5822, 5909, 5984, 5995, 6134, 6514, 6602, 6955, 7001, 7012, 7022, 7090, 7403, 7443, 7654, 7773, 8000, 8003, 8009, 8021, 8049, 8062, 8068, 8082, 8086, 8097, 8099, 8120, 8126, 8152, 8187, 8188, 8196, 8239, 8241, 8282, 8407, 8411, 8452, 8463, 8528, 8531, 8563, 8589, 8591, 8703, 8705, 8779, 8800, 8835, 8848, 8861, 8881, 8883, 8907, 9000, 9027, 9064, 9074, 9075, 9089, 9106, 9133, 9167, 9172, 9173, 9186, 9190, 9196, 9256, 9299, 9310, 9389, 9398, 9410, 9611, 9704, 9761, 9997
Tags: honeypot
CPEs: cpe:/a:openbsd:openssh:8.9p1, cpe:/o:canonical:ubuntu_linux
ts_added
2024-11-26 05:05:00.709000
ts_last_update
2025-12-21 05:05:46.635000

Warden event timeline

DShield event timeline