IP address


.1115.42.97.109
Shodan(more info)
Passive DNS
Tags: Scanner
IP blacklists
Echelon SSH bruteforce
5.42.97.109 is listed on the Echelon SSH bruteforce blacklist.

Description: Multiple SSH authentication attempts detected
Type of feed: primary (feed detail page)

Last checked at: 2026-05-27 09:35:00.288000
Was present on blacklist at: 2026-05-21 09:35, 2026-05-22 09:35, 2026-05-24 09:35, 2026-05-25 09:35, 2026-05-26 09:35, 2026-05-27 09:35

Threat categories

TLRoleCategoryDetails
52 src scan port: 22
25 src login protocol: ssh

Warden events (239)
2026-05-30
ReconScanning (node.9c1411): 15
2026-05-29
ReconScanning (node.9c1411): 18
2026-05-28
ReconScanning (node.9c1411): 14
2026-05-27
ReconScanning (node.9c1411): 9
ReconScanning (node.ce2b59): 9
2026-05-26
ReconScanning (node.ce2b59): 30
ReconScanning (node.9c1411): 7
2026-05-25
ReconScanning (node.ce2b59): 31
2026-05-24
ReconScanning (node.ce2b59): 30
2026-05-23
ReconScanning (node.ce2b59): 29
2026-05-22
ReconScanning (node.ce2b59): 19
2026-05-21
ReconScanning (node.ce2b59): 21
2026-05-20
ReconScanning (node.ce2b59): 7
DShield reports (IP summary, reports)
2026-05-25
Number of reports: 11
Distinct targets: 8
Origin AS
AS9123 - TimeWeb-AS
BGP Prefix
5.42.97.0/24
geo
Russia
🕑 Europe/Moscow
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
5.42.0.0 - 5.42.127.255
last_activity
2026-05-30 13:32:24
last_warden_event
2026-05-30 13:32:24
rep
0.11066323342655215
reserved_range
0
ts_added
2026-05-20 17:57:14.616000
ts_last_update
2026-06-04 17:57:20.169000

Warden event timeline

DShield event timeline

Presence on blacklists