IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (98)
- 2025-10-04
-
- AttemptLogin (node.ce2b59): 5
- AttemptLogin (node.40929a): 1
- 2025-10-03
-
- AttemptLogin (node.ce2b59): 2
- 2025-10-02
-
- AttemptLogin (node.ce2b59): 5
- 2025-10-01
-
- AttemptLogin (node.ce2b59): 5
- 2025-09-30
-
- AttemptLogin (node.ce2b59): 4
- AttemptLogin (node.40929a): 1
- 2025-09-29
-
- AttemptLogin (node.ce2b59): 4
- IntrusionUserCompromise (node.40929a): 1
- 2025-09-28
-
- AttemptLogin (node.985fb4): 2
- AttemptLogin (node.03e7a9): 12
- AttemptLogin (node.7c0a3c): 2
- AttemptLogin (node.e47683): 3
- AttemptLogin (node.b17ef8): 2
- IntrusionUserCompromise (node.985fb4): 1
- IntrusionUserCompromise (node.03e7a9): 6
- IntrusionUserCompromise (node.7c0a3c): 1
- IntrusionUserCompromise (node.b17ef8): 1
- IntrusionUserCompromise (node.40929a): 1
- AttemptLogin (node.ce2b59): 6
- 2025-09-27
-
- AttemptLogin (node.03e7a9): 4
- AttemptLogin (node.b17ef8): 1
- AttemptLogin (node.e47683): 1
- AttemptLogin (node.7c0a3c): 1
- AttemptLogin (node.985fb4): 1
- 2025-08-23
-
- AttemptLogin (node.ce2b59): 1
- 2025-08-22
-
- AttemptLogin (node.ce2b59): 11
- 2025-08-21
-
- AttemptLogin (node.ce2b59): 13
- DShield reports (IP summary, reports)
- 2025-08-20
- Number of reports: 131
- Distinct targets: 79
- 2025-08-21
- Number of reports: 10535
- Distinct targets: 660
- 2025-08-22
- Number of reports: 10680
- Distinct targets: 657
- 2025-08-23
- Number of reports: 10225
- Distinct targets: 660
- 2025-08-24
- Number of reports: 2845
- Distinct targets: 609
- 2025-08-27
- Number of reports: 6960
- Distinct targets: 606
- 2025-08-28
- Number of reports: 10191
- Distinct targets: 617
- 2025-08-29
- Number of reports: 9722
- Distinct targets: 598
- 2025-08-30
- Number of reports: 9667
- Distinct targets: 604
- 2025-08-31
- Number of reports: 9560
- Distinct targets: 603
- 2025-09-01
- Number of reports: 9535
- Distinct targets: 603
- 2025-09-02
- Number of reports: 8990
- Distinct targets: 615
- 2025-09-03
- Number of reports: 2184
- Distinct targets: 550
- 2025-09-05
- Number of reports: 4524
- Distinct targets: 463
- 2025-09-06
- Number of reports: 9924
- Distinct targets: 539
- 2025-09-07
- Number of reports: 9684
- Distinct targets: 524
- 2025-09-08
- Number of reports: 9412
- Distinct targets: 515
- 2025-09-09
- Number of reports: 7018
- Distinct targets: 510
- 2025-09-27
- Number of reports: 250
- Distinct targets: 159
- 2025-09-28
- Number of reports: 1134
- Distinct targets: 160
- 2025-09-29
- Number of reports: 1134
- Distinct targets: 160
- 2025-09-30
- Number of reports: 89
- Distinct targets: 12
- 2025-10-03
- Number of reports: 64
- Distinct targets: 10
- 2025-10-04
- Number of reports: 195
- Distinct targets: 10
- 2025-10-05
- Number of reports: 195
- Distinct targets: 10
- Origin AS
- AS214943 - RAILNET
- AS214940 - KPRONET
- BGP Prefix
- 213.209.157.0/24
- geo
- Germany
- 🕑 Europe/Berlin
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 213.209.128.0 - 213.209.159.255
- last_activity
- 2025-10-04 22:36:40
- last_warden_event
- 2025-10-04 22:36:40
- rep
- 0.20852050781249998
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 22, 445
- Tags: scanner
- CPEs: cpe:/a:openbsd:openssh:8.9p1, cpe:/o:canonical:ubuntu_linux
- ts_added
- 2025-08-21 03:24:36.789000
- ts_last_update
- 2025-10-10 09:52:18.387000
Warden event timeline
DShield event timeline
Presence on blacklists