IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 47.98.0.0/15
- geo
- China, Hangzhou
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 47.96.0.0 - 47.127.255.255
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 13, 17, 19, 24, 25, 43, 49, 79, 95, 98, 102, 104, 175, 179, 195, 221, 311, 389, 465, 480, 513, 541, 666, 675, 689, 771, 789, 831, 873, 992, 995, 1002, 1013, 1119, 1180, 1291, 1293, 1414, 1433, 1447, 1515, 1521, 1599, 1741, 1801, 1911, 1926, 1962, 1964, 1990, 2000, 2008, 2081, 2083, 2091, 2121, 2122, 2150, 2181, 2211, 2222, 2345, 2353, 2376, 2404, 2435, 2455, 2506, 2548, 2628, 2650, 2701, 2995, 3001, 3003, 3004, 3050, 3053, 3081, 3092, 3152, 3166, 3260, 3268, 3269, 3301, 3306, 3389, 3390, 3406, 3510, 4000, 4022, 4063, 4282, 4321, 4369, 4434, 4500, 4506, 4523, 4786, 4808, 4899, 4949, 5007, 5010, 5051, 5100, 5150, 5222, 5245, 5251, 5258, 5321, 5567, 5605, 5696, 5822, 5913, 5915, 5938, 6000, 6001, 6002, 6601, 6602, 7001, 7170, 7173, 7218, 7415, 7443, 7634, 7676, 7700, 7776, 7979, 8007, 8009, 8031, 8032, 8035, 8041, 8057, 8059, 8061, 8067, 8072, 8081, 8083, 8085, 8089, 8092, 8099, 8123, 8126, 8131, 8133, 8135, 8139, 8142, 8162, 8197, 8200, 8250, 8333, 8416, 8425, 8433, 8440, 8444, 8451, 8454, 8456, 8460, 8464, 8494, 8500, 8528, 8545, 8560, 8567, 8568, 8577, 8579, 8595, 8623, 8649, 8688, 8728, 8842, 8869, 8879, 8891, 8900, 8915, 8990, 9005, 9014, 9027, 9038, 9042, 9044, 9051, 9053, 9055, 9060, 9063, 9073, 9083, 9088, 9092, 9095, 9116, 9127, 9151, 9160, 9168, 9173, 9178, 9200, 9216, 9241, 9383, 9398, 9418, 9433, 9600, 9633, 9690, 9898, 9902, 9944, 9998, 9999, 10000, 10001, 10003, 10005, 10037, 10043, 10048, 10066, 10080, 10087, 10255, 10283, 10324, 10477, 10554, 10911, 10943, 11112, 11180, 11211, 11288, 11371, 11920, 12105, 12113, 12131, 12142, 12144, 12152, 12155, 12164, 12200, 12216, 12218, 12219, 12222, 12262, 12265, 12271, 12283, 12287, 12307, 12324, 12333, 12343, 12351, 12393, 12432, 12435, 12462, 12470, 12499, 12504, 12541, 12583, 12587, 14147, 14330, 14344, 14401, 14403, 14825, 14900, 16006, 16042, 16064, 16080, 18005, 18038, 18056, 18066, 18081, 18113, 18245, 18553, 19000, 19015, 19016, 19084, 20100, 20110, 20202, 20256, 20547, 21025, 21254, 21261, 21312, 22067, 22070, 22222, 22556, 23023, 23424, 24245, 25105, 25565, 27017, 27036, 28015, 30003, 30222, 30422, 30622, 30722, 30922, 31444, 31522, 31722, 31922, 32001, 32102, 32122, 32322, 32400, 32422, 32764, 33060, 33389, 35000, 37777, 41794, 41800, 42194, 43008, 44158, 44303, 44305, 44332, 44818, 47990, 49152, 49153, 50004, 50014, 50050, 50100, 51106, 53481, 54138, 55443, 55554, 57787, 60129, 61616, 62078, 63210, 63256, 63257, 63260, 64738
- Tags: honeypot, proxy
- CPEs: cpe:/a:openbsd:openssh:7.6p1, cpe:/a:microsoft:message_queuing, cpe:/a:openbsd:openssh:7.5, cpe:/a:openbsd:openssh:X.X, cpe:/a:mysql:mysql:5.7.31-log, cpe:/o:windriver:vxworks, cpe:/a:f5:nginx, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:5.3, cpe:/a:openbsd:openssh:6.6.1, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:8.0, cpe:/h:cisco:aironet_1200, cpe:/a:cisco:telnet, cpe:/a:openbsd:openssh:7.9, cpe:/a:microsoft:internet_information_services, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/o:microsoft:windows
- ts_added
- 2025-05-05 14:11:15.222000
- ts_last_update
- 2025-05-07 18:11:22.766000
Warden event timeline
DShield event timeline
Presence on blacklists