IP address


--60.251.52.4360-251-52-43.hinet-ip.hinet.net
Shodan(more info)
Passive DNS
Tags: IP in hostname
IP blacklists
DataPlane VNC RFB
60.251.52.43 is listed on the DataPlane VNC RFB blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs initiating<br>an unsolicited VNC remote frame buffer (RFB) session to a remote host.
Type of feed: primary (feed detail page)

Last checked at: 2025-11-26 07:10:01.097000
Was present on blacklist at: 2025-11-19 15:10, 2025-11-19 19:10, 2025-11-20 03:10, 2025-11-20 07:10, 2025-11-20 19:10, 2025-11-21 03:10, 2025-11-21 07:10, 2025-11-21 15:10, 2025-11-21 19:10, 2025-11-22 03:10, 2025-11-22 07:10, 2025-11-22 15:10, 2025-11-22 19:10, 2025-11-23 03:10, 2025-11-23 07:10, 2025-11-23 15:10, 2025-11-23 19:10, 2025-11-24 03:10, 2025-11-24 07:10, 2025-11-24 15:10, 2025-11-24 19:10, 2025-11-25 03:10, 2025-11-25 07:10, 2025-11-25 15:10, 2025-11-25 19:10, 2025-11-26 03:10, 2025-11-26 07:10
Spamhaus XBL CBL
60.251.52.43 is listed on the Spamhaus XBL CBL blacklist.

Description: The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-17 15:10:10.560000
Was present on blacklist at: 2025-12-10 15:10, 2025-12-17 15:10
Spamhaus SBL CSS
60.251.52.43 is listed on the Spamhaus SBL CSS blacklist.

Description: The Spamhaus CSS is part of the SBL. CSS listings will have return code 127.0.0.3 to differentiate from regular SBL listings, which have return code 127.0.0.2.
Type of feed: secondary (DNSBL) (feed detail page)

Last checked at: 2025-12-17 15:10:10.560000
Was present on blacklist at: 2025-12-17 15:10
OTX pulses
[691dc50eb315b09dc89c026b] 2025-11-19 13:24:30.605000 | VNC honeypot logs for 2025/11/19
Author name:jnazario
Pulse modified:2025-11-19 13:24:30.605000
Indicator created:2025-11-19 13:24:31
Indicator role:None
Indicator title:
Indicator expiration:2025-12-19 13:00:00
[691f166da776f634379d6de4] 2025-11-20 13:23:57.487000 | VNC honeypot logs for 2025/11/20
Author name:jnazario
Pulse modified:2025-11-20 13:23:57.487000
Indicator created:2025-11-20 13:23:58
Indicator role:None
Indicator title:
Indicator expiration:2025-12-20 13:00:00
[6920681465ac485e6f6bd00e] 2025-11-21 13:24:36.024000 | VNC honeypot logs for 2025/11/21
Author name:jnazario
Pulse modified:2025-11-21 13:24:36.024000
Indicator created:2025-11-21 13:24:36
Indicator role:None
Indicator title:
Indicator expiration:2025-12-21 13:00:00
Origin AS
AS3462 - HINET
BGP Prefix
60.251.0.0/16
geo
Taiwan, Taipei
🕑 Asia/Taipei
hostname
60-251-52-43.hinet-ip.hinet.net
hostname_class
['ip_in_hostname']
Address block ('inetnum' or 'NetRange' in whois database)
60.250.0.0 - 60.251.255.255
last_activity
2025-11-21 16:36:58.455000
reserved_range
0
Shodan's InternetDB
Open ports: 22, 81, 1723, 4430, 4433
Tags: self-signed, vpn
CPEs: cpe:/a:openbsd:openssh:7.4, cpe:/a:f5:nginx
ts_added
2025-11-19 15:10:01.866000
ts_last_update
2025-12-18 15:10:13.085000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses