General Information

Submitter Diversity: Very High
Risk (0-10)details: 8
RESEARCHER: THIS IP IS USED FOR INTERNET WIDE RESEARCH SCANS
IP Address (click for more detail): 184.105.247.252
Hostname: scan-21b.shadowserver.io
Country:  US
ASN: 6939
AS Name:  HURRICANE - Hurricane Electric LLC, US
Network:  184.104.0.0/15 (184.104.0.0-184.105.255.255) 184.106.0.0
Reports: 17002
Targets: 2215
First Reported: 2021-09-11
Most Recent Report: 2026-10-08
Comment: Shadowserver.org Scanner
Abuse Contact for AS6939: abuse@he.net
Links to articles about the IP from rosti.bin.re

Note: We update the data once an hour. To refresh the data, click here. Not all source IPs in our database are "attackers". There are a few common false positives. For example, hosts that participate in P2P networks, mail servers, load balancers and DNS servers are some of the most common issues. For details, click on the number of reports. Clicking on the number of reports may allow you to conclude if a report is a false positive or not. Scroll down for information from other data feeds.

SSH/Telnet Logs

Username and Password Details
Total AttemptsUsernames/day Passwords/dayFirst SeenLast Seen
6162018-07-062019-06-25

Web Honeypot Logs

Date Reports Different URLs Different User Agents
2026-10-091034
2026-10-082339
2026-10-071178
2026-10-0621716
2026-10-0533418
2026-10-0419814
2026-10-0329815
2026-10-0229615
2026-10-011439
2026-09-3033819
2026-09-2949922
2026-09-2816210
2026-09-2718713
2026-09-261427

For more details about the web honeypot, see the Weblogs Page. Do not use these reports to identify IP addresses as "bad" for now.

External Threat Feeds

This data was retrieved from various external data feeds.

First Seen Last Seen Feed
2015-03-142026-10-08CI Army List
2018-11-262026-10-08Shadowserver
Check Threatstop for more data link arrow