IP address


.000217.160.25.65
Shodan(more info)
Passive DNS
Tags:

Threat categories

TLRoleCategoryDetails
50 src scan

DShield reports (IP summary, reports)
2026-06-02
Number of reports: 38
Distinct targets: 21
2026-06-03
Number of reports: 38
Distinct targets: 21
Origin AS
AS8560 - ONEANDONE-AS
BGP Prefix
217.160.0.0/16
geo
Germany
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
217.160.0.0 - 217.160.255.255
rep
0.00019411133867752728
reserved_range
0
Shodan's InternetDB
Open ports: 21, 22, 53, 80, 88, 111, 443, 3128, 3790, 4444, 5500, 7331, 8008, 8080, 8090, 8443, 8880
Tags: self-signed, c2
CPEs: cpe:/a:python:python:3.13.5, cpe:/a:getbootstrap:bootstrap, cpe:/a:apache:tomcat, cpe:/a:openbsd:openssh:10.0p2, cpe:/o:linux:linux_kernel, cpe:/a:palletsprojects:flask:3.1.3, cpe:/a:mariadb_project:mariadb, cpe:/a:nodejs:node.js, cpe:/a:facebook:react, cpe:/a:expressjs:express, cpe:/o:debian:debian_linux, cpe:/a:jquery:jquery, cpe:/a:jquery:jquery_ui:1.12.1, cpe:/a:pureftpd:pure-ftpd, cpe:/a:oracle:jre, cpe:/a:f5:nginx
ts_added
2026-06-03 05:00:58.093000
ts_last_update
2026-06-05 05:01:04.322000

Warden event timeline

DShield event timeline