IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (3)
- 2025-04-28
-
- IntrusionUserCompromise (node.40929a): 1
- 2025-04-22
-
- IntrusionUserCompromise (node.40929a): 1
- 2025-04-11
-
- IntrusionUserCompromise (node.40929a): 1
- DShield reports (IP summary, reports)
- 2025-05-01
- Number of reports: 10
- Distinct targets: 6
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 39.104.0.0/15
- geo
- China, Beijing
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 39.104.0.0 - 39.107.255.255
- last_activity
- 2025-04-28 19:50:19.847000
- last_warden_event
- 2025-04-28 19:50:19.847000
- rep
- 0.011904761904761906
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 22, 23, 25, 37, 49, 53, 79, 80, 90, 110, 113, 119, 135, 143, 179, 195, 221, 264, 389, 444, 503, 515, 541, 548, 554, 636, 666, 789, 873, 993, 1023, 1025, 1111, 1119, 1153, 1200, 1234, 1337, 1433, 1494, 1521, 1800, 1883, 1926, 1962, 2003, 2008, 2012, 2067, 2068, 2081, 2083, 2087, 2111, 2154, 2181, 2323, 2332, 2345, 2375, 2376, 2382, 2404, 2455, 2569, 2628, 2762, 3050, 3073, 3077, 3256, 3260, 3268, 3269, 3306, 3388, 3403, 3408, 3780, 3790, 3838, 3950, 4000, 4022, 4150, 4157, 4242, 4282, 4321, 4369, 4443, 4444, 4505, 4700, 4786, 4911, 5010, 5025, 5070, 5172, 5201, 5222, 5269, 5672, 5858, 5938, 5984, 6001, 6264, 6379, 6580, 6633, 6666, 6667, 6668, 6697, 7001, 7071, 7171, 7218, 7777, 7788, 7999, 8002, 8009, 8043, 8080, 8081, 8085, 8087, 8089, 8099, 8101, 8126, 8333, 8545, 8590, 8649, 8821, 8829, 8834, 8857, 8880, 8887, 8889, 9000, 9001, 9013, 9017, 9021, 9042, 9091, 9100, 9191, 9199, 9211, 9219, 9221, 9306, 9418, 9443, 9445, 9530, 9600, 9633, 9761, 9876, 9943, 9944, 9999, 10000, 10001, 10051, 10250, 10554, 10909, 10911, 11000, 11112, 11210, 11288, 11300, 12000, 13047, 14265, 14344, 16010, 18080, 18081, 20000, 20547, 20880, 21025, 21379, 22001, 22556, 24245, 25565, 26656, 28015, 28080, 30222, 30301, 30822, 31222, 31337, 31422, 31622, 32322, 32764, 33022, 33060, 33322, 34022, 34122, 34222, 34622, 34722, 34822, 35122, 36022, 36122, 36222, 36522, 37777, 37822, 38222, 38322, 41443, 45322, 47990, 48822, 50100, 50322, 51235, 51322, 51522, 51622, 52322, 52422, 53622, 54138, 54422, 54722, 54822, 55000, 55022, 55322, 55422, 55443, 55553, 55554, 55822, 55922, 56222, 57122, 57222, 57322, 57522, 58922, 60129, 61613, 62078, 63210, 63260
- Tags: proxy, eol-product, honeypot, database
- CPEs: cpe:/a:tiny:tinymce, cpe:/a:f5:nginx:1.12.2, cpe:/a:openbsd:openssh:X.X, cpe:/a:openbsd:openssh:8.2p1, cpe:/a:openbsd:openssh:5.3, cpe:/a:f5:nginx, cpe:/a:openbsd:openssh:7.5, cpe:/a:realvnc:realvnc:::enterprise, cpe:/o:canonical:ubuntu_linux, cpe:/a:apache:subversion, cpe:/a:eset:nod32_antivirus:99, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:openbsd:openssh:7.6p1, cpe:/a:cisco:ssh:3524665.35, cpe:/a:f5:nginx:1.22.1, cpe:/o:microsoft:windows, cpe:/o:cisco:ios, cpe:/a:openbsd:openssh:8.6, cpe:/a:oracle:mysql:5.1.35-analyticdb, cpe:/a:apache:dubbo, cpe:/a:openbsd:openssh:8.0
- ts_added
- 2025-04-12 04:13:02.624000
- ts_last_update
- 2025-05-07 04:13:10.133000
Warden event timeline
DShield event timeline
Presence on blacklists