IP address


--216.158.232.43
Shodan(more info)
Passive DNS
Tags:
OTX pulses
[6938577d1df39d03f2dc4345] 2025-12-09 17:08:13.495000 | React2Shell Deep Dive: CVE-2025-55182 Exploit Mechanics
Author name:AlienVault
Pulse modified:2025-12-09 17:24:01.482000
Indicator created:2025-12-09 17:08:14
Indicator role:None
Indicator title:
Indicator expiration:2026-01-08 17:00:00
[69398505e9eef97b07197db2] 2025-12-10 14:34:45.882000 | PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182
Author name:AlienVault
Pulse modified:2025-12-10 14:41:22.889000
Indicator created:2025-12-10 14:34:46
Indicator role:None
Indicator title:
Indicator expiration:2026-01-09 14:00:00
Origin AS
AS19318 - NJIIX-AS-1
BGP Prefix
216.158.224.0/20
geo
United States
🕑 America/Chicago
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
216.158.224.0 - 216.158.239.255
last_activity
2025-12-10 16:37:21.229000
reserved_range
0
Shodan's InternetDB
Open ports: 22, 80, 443, 2022, 3306, 8096, 8443, 25565
Tags: videogame, database, eol-product
CPEs: cpe:/a:f5:nginx:1.18.0, cpe:/o:linux:linux_kernel, cpe:/o:canonical:ubuntu_linux, cpe:/a:minecraft:minecraft:1.18.2, cpe:/a:jellyfin:jellyfin:10.10.7, cpe:/a:openbsd:openssh:8.9p1, cpe:/a:mariadb:mariadb, cpe:/a:lodash:lodash, cpe:/a:jquery:jquery, cpe:/a:microsoft:asp.net
ts_added
2025-12-09 20:36:55.070000
ts_last_update
2025-12-20 20:37:00.236000

Warden event timeline

DShield event timeline

OTX pulses