IP address
Shodan(more info)

Passive DNS

- IP blacklists
- Warden events (3)
- 2025-04-25
-
- IntrusionUserCompromise (node.40929a): 1
- 2025-04-24
-
- AttemptLogin (node.ce2b59): 1
- 2025-04-21
-
- IntrusionUserCompromise (node.40929a): 1
- Origin AS
- AS37963 - CNNIC-ALIBABA-CN-NET-AP
- BGP Prefix
- 59.110.128.0/17
- geo
- China, Beijing
- 🕑 Asia/Shanghai
- hostname
- (null)
- Address block ('inetnum' or 'NetRange' in whois database)
- 59.110.0.0 - 59.111.255.255
- last_activity
- 2025-04-25 18:03:31.510000
- last_warden_event
- 2025-04-25 18:03:31.510000
- rep
- 0.007142857142857143
- reserved_range
- 0
- Shodan's InternetDB
- Open ports: 11, 15, 17, 19, 21, 22, 37, 43, 49, 53, 70, 79, 80, 97, 102, 104, 111, 113, 119, 135, 175, 179, 195, 221, 234, 263, 389, 427, 443, 444, 465, 503, 513, 515, 548, 554, 593, 666, 685, 771, 789, 805, 808, 853, 873, 947, 992, 993, 1023, 1025, 1080, 1081, 1153, 1180, 1200, 1207, 1234, 1337, 1414, 1433, 1443, 1452, 1455, 1521, 1604, 1650, 1700, 1723, 1801, 1911, 1922, 1947, 1974, 2000, 2002, 2003, 2016, 2057, 2081, 2083, 2087, 2154, 2181, 2196, 2211, 2222, 2323, 2332, 2345, 2376, 2404, 2548, 2555, 2558, 2567, 2628, 2709, 2761, 2762, 3001, 3003, 3048, 3050, 3064, 3066, 3077, 3098, 3105, 3117, 3131, 3148, 3173, 3177, 3192, 3196, 3260, 3268, 3269, 3299, 3306, 3310, 3352, 3388, 3400, 3551, 3622, 3690, 3790, 4000, 4063, 4064, 4148, 4150, 4157, 4242, 4282, 4430, 4434, 4444, 4455, 4459, 4461, 4482, 4531, 4786, 4840, 4899, 4911, 5001, 5007, 5009, 5010, 5070, 5190, 5201, 5230, 5269, 5279, 5280, 5432, 5435, 5454, 5495, 5598, 5608, 5660, 5672, 5858, 5938, 5984, 6000, 6001, 6002, 6004, 6061, 6070, 6161, 6264, 6379, 6602, 6605, 6633, 6650, 6653, 6667, 6697, 7001, 7007, 7057, 7071, 7078, 7171, 7218, 7331, 7415, 7434, 7443, 7465, 7603, 7676, 7788, 7980, 8009, 8024, 8031, 8034, 8066, 8072, 8076, 8081, 8083, 8084, 8085, 8087, 8101, 8107, 8116, 8126, 8139, 8140, 8141, 8147, 8150, 8159, 8181, 8200, 8243, 8251, 8322, 8333, 8382, 8431, 8448, 8500, 8519, 8525, 8545, 8550, 8554, 8605, 8640, 8728, 8766, 8789, 8833, 8834, 8851, 8855, 8860, 8880, 8889, 8943, 8988, 9000, 9002, 9016, 9036, 9043, 9051, 9058, 9071, 9076, 9083, 9091, 9092, 9095, 9116, 9137, 9139, 9147, 9151, 9180, 9202, 9216, 9219, 9273, 9292, 9302, 9306, 9308, 9333, 9398, 9418, 9441, 9443, 9444, 9456, 9505, 9529, 9530, 9550, 9633, 9682, 9761, 9872, 9876, 9898, 9902, 9916, 9943, 9998, 9999, 10001, 10028, 10038, 10086, 10181, 10444, 10554, 10911, 11112, 11211, 11288, 11300, 12000, 12016, 12084, 12088, 12106, 12125, 12141, 12153, 12179, 12245, 12326, 12344, 12345, 12349, 12363, 12375, 12413, 12423, 12424, 12427, 12459, 12479, 12538, 12559, 12572, 12584, 14024, 14082, 14147, 14265, 14895, 15038, 15672, 16051, 16078, 16095, 16097, 16666, 16993, 17772, 18003, 18004, 18022, 18036, 18042, 18052, 18061, 18063, 18065, 18245, 19000, 19016, 19022, 19080, 20000, 20060, 20082, 20547, 20880, 20892, 21025, 21245, 21250, 21279, 21280, 21292, 21379, 21443, 22403, 22703, 23084, 23184, 24808, 25001, 25002, 25004, 25006, 25565, 27015, 27017, 28015, 30002, 30003, 30004, 30011, 30019, 30027, 30473, 31337, 32202, 32522, 32764, 33122, 33222, 33622, 33722, 34522, 34822, 35000, 35022, 35122, 35153, 35250, 35522, 35822, 36122, 37122, 37222, 37777, 38622, 38922, 39022, 39622, 39822, 40422, 40522, 40722, 41322, 41722, 41800, 41922, 42420, 42522, 42822, 43022, 43422, 44022, 44304, 44307, 44341, 44522, 44622, 44818, 45122, 45522, 45722, 46622, 47001, 47122, 47990, 48122, 48222, 48822, 48922, 49122, 49200, 49222, 49322, 49522, 49688, 49722, 50000, 50008, 50022, 50100, 50122, 50322, 50422, 50622, 51235, 51622, 51822, 52010, 52022, 52422, 52951, 53022, 53122, 53422, 53482, 53722, 54138, 54922, 55000, 55055, 55553, 56622, 56722, 57022, 57222, 57781, 57822, 58022, 58622, 59622, 59922, 60021, 60129, 61613, 62078, 62443, 63210, 63256, 63260, 64477
- Tags: proxy, eol-product, honeypot
- CPEs: cpe:/a:microsoft:internet_information_services, cpe:/a:apache:dubbo, cpe:/a:mysql:mysql, cpe:/a:openbsd:openssh:6.6.1p1, cpe:/o:cisco:ios, cpe:/a:microsoft:message_queuing, cpe:/a:vmware:rabbitmq:3.8.2, cpe:/a:realvnc:realvnc:::enterprise, cpe:/a:openbsd:openssh:5.3, cpe:/a:eset:nod32_antivirus:99, cpe:/a:apache:subversion, cpe:/a:vsftpd:vsftpd:3.0.2, cpe:/a:openbsd:openssh:7.5, cpe:/a:f5:nginx:1.22.1, cpe:/o:microsoft:windows, cpe:/a:f5:nginx, cpe:/o:canonical:ubuntu_linux, cpe:/a:openbsd:openssh:7.4, cpe:/a:openbsd:openssh:7.6p1, cpe:/a:openbsd:openssh:8.0, cpe:/a:openbsd:openssh:6.6.1, cpe:/a:jquery:jquery:3.4.1, cpe:/a:openbsd:openssh:8.2p1, cpe:/a:cisco:ssh:3524665.35, cpe:/a:f5:nginx:1.16.1, cpe:/a:openbsd:openssh:7.2p2, cpe:/a:openbsd:openssh:X.X
- ts_added
- 2025-04-22 04:00:14.624000
- ts_last_update
- 2025-05-07 04:00:26.423000
Warden event timeline
DShield event timeline
Presence on blacklists