🦞 OpenClaw Exposure Watchboard
This page lists publicly reachable active OpenClaw instances for defensive awareness. If this is your deployment, enable authentication, remove direct public exposure, and patch immediately.
Exposed Instances: 1076720 Page: 122 / 10768 (100 per page) Showing: 12101-12200 Last Imported: 10/09/2026, 14:51:48
🇨🇳 507,651
🇺🇸 312,129
Build With Vivgrid
Explore Vivgrid Ship Secure Enterprise AI Agents 10× Faster with vivgrid.com
Vivgrid gives you authentication, model gateway, tool control, cost tracking, and enterprise observability — everything you need to ship AI agents safely at scale.
| Endpoint | Assistant Name | Country | auth_required | is_active | has_leaked_creds | asn | asn_name | org | first_seen | last_seen | asi_has_breach | asi_has_threat_actor | asi_threat_actors | asi_cves | asi_enriched_at | asi_domains |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 84.170.201.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS3320 | Internet service provider operations | Deutsche Telekom | 28/08/2026, 03:34:10 | 28/08/2026, 09:56:03 | Yes | No | - | - | 28/08/2026, 04:16:48 | telekom.de |
| 1.52.208.•••:18789 | - | 🇻🇳 Vietnam | Yes | false | Leaked | AS18403 | FPT Telecom Company | FPT Telecom | 28/08/2026, 03:34:10 | 28/08/2026, 09:56:02 | Yes | No | - | CVE-2009-4593 | 28/08/2026, 04:16:49 | fpt.com |
| 49.81.177.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | ChinaNet Jiangsu | 28/08/2026, 03:32:21 | 03/09/2026, 10:17:11 | Yes | No | - | - | 28/08/2026, 06:26:43 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 183.23.149.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Guangdong | 28/08/2026, 03:32:20 | 31/08/2026, 21:43:58 | Yes | No | - | - | 28/08/2026, 06:26:53 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 8.163.71.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 28/08/2026, 03:32:20 | 09/09/2026, 22:27:01 | - | - | - | - | - | - |
| 218.73.14.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | CHINANET-ZJ-TZ | 28/08/2026, 03:32:18 | 28/08/2026, 10:36:18 | - | - | - | - | - | - |
| 116.234.98.•••:18789 | - | 🇨🇳 China mainland | - | false | Leaked | AS4812 | China Telecom (Group) | ChinaNet Shanghai | 28/08/2026, 03:32:18 | 28/08/2026, 10:36:17 | Yes | No | - | - | 28/08/2026, 07:48:37 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 34.151.247.•••:18789 | Assistant | 🇺🇸 United States | Yes | false | Clean | AS396982 | Google LLC | 28/08/2026, 03:32:17 | 02/09/2026, 20:52:01 | No | - | - | - | 22/08/2026, 07:48:40 | - | |
| 84.170.201.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS3320 | Internet service provider operations | Deutsche Telekom | 28/08/2026, 03:32:16 | 28/08/2026, 10:36:16 | Yes | No | - | - | 28/08/2026, 07:48:46 | telekom.de |
| 13.36.171.•••:18789 | - | 🇫🇷 France | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services | 28/08/2026, 03:30:19 | 01/09/2026, 22:09:40 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 03:35:02 | - |
| 169.58.234.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS51167 | Contabo GmbH | Contabo | 28/08/2026, 02:53:48 | 09/09/2026, 23:14:10 | - | - | - | - | - | - |
| 39.105.90.•••:443 | - | 🇽🇽 XX | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Unknown | 28/08/2026, 02:53:48 | 09/09/2026, 06:57:13 | Yes | No | - | - | 03/09/2026, 08:56:25 | aliyun.com |
| 143.198.30.•••:80 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 28/08/2026, 02:53:48 | 10/09/2026, 05:38:59 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 28/08/2026, 02:54:36 | - |
| 36.225.153.•••:443 | - | 🇹🇼 Taiwan | Yes | false | Clean | AS3462 | Data Communication Business Group | Chunghwa Telecom Data Group | 28/08/2026, 02:53:47 | 28/08/2026, 22:45:10 | No | No | - | - | 22/08/2026, 02:54:45 | - |
| 14.216.132.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Guangdong | 28/08/2026, 02:53:47 | 28/08/2026, 14:12:22 | Yes | No | - | CVE-2013-4548, CVE-2014-1692, CVE-2014-2532, CVE-2014-2653, CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2015-8325, CVE-2016-0777, CVE-2016-0778, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-1908, CVE-2016-20012, CVE-2016-3115, CVE-2016-6210, CVE-2016-6515, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 02:54:47 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 32.184.74.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 28/08/2026, 02:53:45 | 05/09/2026, 20:04:17 | - | - | - | - | - | - |
| 39.105.90.•••:18789 | - | 🇽🇽 XX | - | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Unknown | 28/08/2026, 02:51:58 | 09/09/2026, 01:57:53 | Yes | No | - | - | 03/09/2026, 04:00:06 | aliyun.com |
| 143.198.30.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 28/08/2026, 02:51:58 | 10/09/2026, 00:37:58 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 28/08/2026, 05:03:05 | - |
| 36.225.153.•••:18789 | - | 🇹🇼 Taiwan | - | false | Clean | AS3462 | Data Communication Business Group | Chunghwa Telecom Data Group | 28/08/2026, 02:51:57 | 28/08/2026, 17:02:56 | No | No | - | - | 22/08/2026, 05:03:11 | - |
| 14.216.132.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Guangdong | 28/08/2026, 02:51:57 | 28/08/2026, 08:31:30 | Yes | No | - | CVE-2013-4548, CVE-2014-1692, CVE-2014-2532, CVE-2014-2653, CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2015-8325, CVE-2016-0777, CVE-2016-0778, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-1908, CVE-2016-20012, CVE-2016-3115, CVE-2016-6210, CVE-2016-6515, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 05:03:14 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 14.216.132.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Guangdong | 28/08/2026, 02:50:02 | 28/08/2026, 09:54:09 | Yes | No | - | CVE-2013-4548, CVE-2014-1692, CVE-2014-2532, CVE-2014-2653, CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2015-8325, CVE-2016-0777, CVE-2016-0778, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-1908, CVE-2016-20012, CVE-2016-3115, CVE-2016-6210, CVE-2016-6515, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 06:26:18 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 36.225.153.•••:18789 | - | 🇹🇼 Taiwan | - | false | Clean | AS3462 | Data Communication Business Group | Chunghwa Telecom Data Group | 28/08/2026, 02:48:02 | 30/08/2026, 02:47:25 | No | No | - | - | 22/08/2026, 03:34:58 | - |
| 185.47.152.•••:18789 | - | 🇧🇾 Belarus | Yes | false | Clean | AS202090 | Aktivnie Tehnologii LLC | Aktivnie Tehnologii | 28/08/2026, 02:48:02 | 30/08/2026, 02:47:24 | - | - | - | - | - | - |
| 114.99.136.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | ChinaNet Anhui Province Network | 28/08/2026, 02:11:26 | 31/08/2026, 16:36:23 | Yes | No | - | - | 28/08/2026, 05:44:47 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 115.194.17.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Hangzhou | 28/08/2026, 02:11:26 | 28/08/2026, 13:29:42 | No | No | - | - | 22/08/2026, 05:44:50 | - |
| 8.163.53.•••:18789 | - | 🇸🇬 Singapore | Yes | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 28/08/2026, 02:11:26 | 28/08/2026, 13:29:41 | - | - | - | - | - | - |
| 2408:8210:9c03:ee4::1:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom | 28/08/2026, 02:11:26 | 31/08/2026, 15:53:50 | - | - | - | - | - | - |
| 171.213.234.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Sichuan | 28/08/2026, 02:11:26 | 28/08/2026, 13:29:41 | No | No | - | - | 22/08/2026, 05:45:02 | - |
| 110.42.234.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 28/08/2026, 02:11:25 | 09/09/2026, 04:50:01 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 05:45:05 | tencentcloud.com |
| 82.207.236.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS8881 | 1&1 Versatel GmbH | VT Customer Pool | 28/08/2026, 02:11:25 | 28/08/2026, 13:29:40 | Yes | No | - | - | 28/08/2026, 05:45:13 | 1und1.net, versatel.de |
| 32.185.217.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS16509 | Amazon.com, Inc. | Amazon | 28/08/2026, 02:11:24 | 28/08/2026, 13:29:40 | - | - | - | - | - | - |
| 199.244.48.•••:443 | - | 🇺🇸 United States | Yes | false | Clean | AS36007 | Kamatera, Inc. | CloudWebManage NY | 28/08/2026, 02:11:24 | 28/08/2026, 14:12:26 | No | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Turla APT Group, Volt Typhoon | CVE-2022-41741, CVE-2022-41742, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 28/08/2026, 02:53:57 | - |
| 2.143.42.•••:18789 | - | 🇪🇸 Spain | Yes | false | Clean | AS3352 | TELEFONICA DE ESPANA S.A.U. | IP Services Network | 28/08/2026, 02:11:24 | 28/08/2026, 14:12:25 | No | No | - | - | 22/08/2026, 02:53:59 | - |
| 187.250.170.•••:18789 | - | 🇲🇽 Mexico | Yes | false | Leaked | AS8151 | Uninet S.A. de C.V. | Telefonos del Noroeste | 28/08/2026, 02:11:23 | 28/08/2026, 14:12:25 | Yes | No | - | CVE-2006-20001, CVE-2007-6750, CVE-2008-2364, CVE-2008-2939, CVE-2009-1891, CVE-2009-3094, CVE-2009-3095, CVE-2009-3555, CVE-2009-3560, CVE-2009-3720, CVE-2010-0425, CVE-2010-0434, CVE-2010-1452, CVE-2010-1623, CVE-2011-0419, CVE-2011-3192, CVE-2011-3368, CVE-2011-3607, CVE-2011-3639, CVE-2011-4317, CVE-2011-4415, CVE-2012-0031, CVE-2012-0053, CVE-2013-1862, CVE-2015-0228, CVE-2016-8612, CVE-2017-9788, CVE-2017-9798, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-21027, CVE-2018-21028, CVE-2019-7659, CVE-2021-34798, CVE-2021-39275, CVE-2021-40438, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-37436, CVE-2023-31122, CVE-2023-38709, CVE-2024-40898, CVE-2025-49812 | 28/08/2026, 02:54:11 | telmexit.com, telmex.net, infinitummail.com, telmex.com, telmexomsasi.com, telmexmail.com, telnor.com, eninfinitum.com, fundaciontelmextelcel.org, infinitummovil.net |
| 20.69.152.•••:80 | - | 🇺🇸 United States | Yes | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 28/08/2026, 02:11:23 | 07/09/2026, 04:47:56 | - | - | - | - | - | - |
| 114.99.136.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | ChinaNet Anhui Province Network | 28/08/2026, 02:09:36 | 31/08/2026, 10:57:21 | Yes | No | - | - | 28/08/2026, 05:01:54 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 8.163.53.•••:18789 | - | 🇸🇬 Singapore | Yes | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 28/08/2026, 02:09:36 | 29/08/2026, 17:00:36 | - | - | - | - | - | - |
| 79.192.2.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS3320 | Internet service provider operations | Deutsche Telekom | 28/08/2026, 02:09:35 | 07/09/2026, 04:45:56 | Yes | No | - | - | 28/08/2026, 05:02:04 | telekom.de |
| 2408:8210:9c03:ee4::1:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom | 28/08/2026, 02:09:35 | 31/08/2026, 10:15:21 | - | - | - | - | - | - |
| 171.213.234.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Sichuan | 28/08/2026, 02:09:35 | 28/08/2026, 07:49:12 | No | No | - | - | 22/08/2026, 05:02:08 | - |
| 110.42.234.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 28/08/2026, 02:09:35 | 09/09/2026, 00:33:05 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 05:02:12 | tencentcloud.com |
| 82.207.236.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS8881 | 1&1 Versatel GmbH | VT Customer Pool | 28/08/2026, 02:09:34 | 28/08/2026, 07:49:10 | Yes | No | - | - | 28/08/2026, 05:02:20 | 1und1.net, versatel.de |
| 32.185.217.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS16509 | Amazon.com, Inc. | Amazon | 28/08/2026, 02:09:34 | 28/08/2026, 07:49:10 | - | - | - | - | - | - |
| 199.244.48.•••:18789 | - | 🇺🇸 United States | - | false | Clean | AS36007 | Kamatera, Inc. | CloudWebManage NY | 28/08/2026, 02:09:33 | 28/08/2026, 07:49:10 | No | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Turla APT Group, Volt Typhoon | CVE-2022-41741, CVE-2022-41742, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 28/08/2026, 05:02:27 | - |
| 2.143.42.•••:18789 | - | 🇪🇸 Spain | Yes | false | Clean | AS3352 | TELEFONICA DE ESPANA S.A.U. | IP Services Network | 28/08/2026, 02:09:32 | 28/08/2026, 07:49:09 | No | No | - | - | 22/08/2026, 05:02:30 | - |
| 187.250.170.•••:18789 | - | 🇲🇽 Mexico | Yes | false | Leaked | AS8151 | Uninet S.A. de C.V. | Telefonos del Noroeste | 28/08/2026, 02:09:31 | 28/08/2026, 08:31:35 | Yes | No | - | CVE-2006-20001, CVE-2007-6750, CVE-2008-2364, CVE-2008-2939, CVE-2009-1891, CVE-2009-3094, CVE-2009-3095, CVE-2009-3555, CVE-2009-3560, CVE-2009-3720, CVE-2010-0425, CVE-2010-0434, CVE-2010-1452, CVE-2010-1623, CVE-2011-0419, CVE-2011-3192, CVE-2011-3368, CVE-2011-3607, CVE-2011-3639, CVE-2011-4317, CVE-2011-4415, CVE-2012-0031, CVE-2012-0053, CVE-2013-1862, CVE-2015-0228, CVE-2016-8612, CVE-2017-9788, CVE-2017-9798, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-21027, CVE-2018-21028, CVE-2019-7659, CVE-2021-34798, CVE-2021-39275, CVE-2021-40438, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-37436, CVE-2023-31122, CVE-2023-38709, CVE-2024-40898, CVE-2025-49812 | 28/08/2026, 05:02:41 | telmexit.com, telmex.net, infinitummail.com, telmex.com, telmexomsasi.com, telmexmail.com, telnor.com, eninfinitum.com, fundaciontelmextelcel.org, infinitummovil.net |
| 20.69.152.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 28/08/2026, 02:09:30 | 07/09/2026, 00:29:15 | - | - | - | - | - | - |
| 79.192.2.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS3320 | Internet service provider operations | Deutsche Telekom | 28/08/2026, 02:07:31 | 07/09/2026, 06:55:10 | Yes | No | - | - | 28/08/2026, 06:25:30 | telekom.de |
| 171.213.234.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Sichuan | 28/08/2026, 02:07:31 | 28/08/2026, 09:11:53 | No | No | - | - | 22/08/2026, 06:25:33 | - |
| 110.42.234.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 28/08/2026, 02:07:31 | 09/09/2026, 02:38:27 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 06:25:36 | tencentcloud.com |
| 82.207.236.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS8881 | 1&1 Versatel GmbH | VT Customer Pool | 28/08/2026, 02:07:30 | 28/08/2026, 09:11:52 | Yes | No | - | - | 28/08/2026, 06:25:42 | 1und1.net, versatel.de |
| 32.185.217.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS16509 | Amazon.com, Inc. | Amazon | 28/08/2026, 02:07:30 | 28/08/2026, 09:11:52 | - | - | - | - | - | - |
| 2.143.42.•••:18789 | - | 🇪🇸 Spain | Yes | false | Clean | AS3352 | TELEFONICA DE ESPANA S.A.U. | IP Services Network | 28/08/2026, 02:07:29 | 28/08/2026, 09:11:50 | No | No | - | - | 22/08/2026, 06:25:48 | - |
| 18.162.239.•••:443 | - | 🇭🇰 Hong Kong | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Hong Kong | 28/08/2026, 01:28:50 | 28/08/2026, 12:47:19 | No | - | - | - | 22/08/2026, 05:44:09 | - |
| 104.207.88.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS22612 | Namecheap, Inc. | Namecheap | 28/08/2026, 01:28:49 | 31/08/2026, 12:23:55 | - | - | - | - | - | - |
| 2409:8a3c:4702:7664:7804:e311:deef:2:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS24444 | Shandong Mobile Communication Company Limited | China Mobile | 28/08/2026, 01:28:48 | 28/08/2026, 12:47:17 | - | - | - | - | - | - |
| 112.114.202.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Yunnan | 28/08/2026, 01:28:47 | 31/08/2026, 10:17:22 | - | - | - | - | - | - |
| 1.92.73.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 28/08/2026, 01:28:47 | 09/09/2026, 03:24:54 | Yes | No | - | CVE-2023-44487, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 05:44:36 | smartcom.cc, huawei.com, huaweidevice.com |
| 106.81.36.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | Chinanet Chongqing | 28/08/2026, 01:28:47 | 28/08/2026, 13:29:45 | No | No | - | - | 22/08/2026, 05:44:35 | - |
| 159.75.243.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 28/08/2026, 01:28:46 | 09/09/2026, 16:10:37 | No | No | - | CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-7347 | 28/08/2026, 05:44:40 | - |
| 16.78.91.•••:18789 | - | 🇸🇬 Singapore | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Jakarta | 28/08/2026, 01:26:59 | 28/08/2026, 07:07:10 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 05:01:02 | - |
| 117.30.126.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Fujian | 28/08/2026, 01:26:58 | 31/08/2026, 04:32:17 | Yes | No | - | - | 28/08/2026, 05:01:13 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 18.162.239.•••:18789 | - | 🇭🇰 Hong Kong | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Hong Kong | 28/08/2026, 01:26:58 | 28/08/2026, 07:07:09 | No | - | - | - | 22/08/2026, 05:01:18 | - |
| 104.207.88.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS22612 | Namecheap, Inc. | Namecheap | 28/08/2026, 01:26:56 | 31/08/2026, 06:41:20 | - | - | - | - | - | - |
| 2409:8a3c:4702:7664:7804:e311:deef:2:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS24444 | Shandong Mobile Communication Company Limited | China Mobile | 28/08/2026, 01:26:55 | 28/08/2026, 07:07:06 | - | - | - | - | - | - |
| 112.114.202.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Yunnan | 28/08/2026, 01:26:53 | 01/09/2026, 13:37:31 | - | - | - | - | - | - |
| 1.92.73.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 28/08/2026, 01:26:53 | 08/09/2026, 23:07:37 | Yes | No | - | CVE-2023-44487, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 01:26:58 | smartcom.cc, huawei.com, huaweidevice.com |
| 106.81.36.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | Chinanet Chongqing | 28/08/2026, 01:26:53 | 28/08/2026, 07:49:16 | No | No | - | - | 22/08/2026, 01:26:59 | - |
| 159.75.243.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 28/08/2026, 01:26:53 | 09/09/2026, 11:52:47 | No | No | - | CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-7347 | 28/08/2026, 01:27:04 | - |
| 47.84.81.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 28/08/2026, 01:25:06 | 10/09/2026, 11:56:57 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 03:36:29 | hichina.com, alibaba-inc.com |
| 18.162.239.•••:18789 | - | 🇭🇰 Hong Kong | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Hong Kong | 28/08/2026, 01:25:04 | 28/08/2026, 08:29:42 | No | - | - | - | 22/08/2026, 03:36:41 | - |
| 172.67.193.•••:18789 | - | 🇺🇸 United States | - | false | Leaked | AS13335 | Cloudflare, Inc. | Cloudflare | 28/08/2026, 01:25:03 | 28/08/2026, 08:29:40 | Yes | No | - | - | 28/08/2026, 03:36:54 | ctautoworks.com.au, itts.co.th, shenji-titanium.com, co.nl, teamdmax.com.au, wisdomxj.cn, deeprootslawncare.com, catuan.net, cgmprecast.com, cwsse.com.cn, world-architects.com, enrollonehealth.com, goldeasttrading.ru, limpiom.net, xjkrx.cn, jetreacare.com, intermountainphysician.org, fuhuake.com, abpincorp.com, xintec.hk, hqpots.com, meter.ln.cn, anlink.net, habberstadpowersports.com, yac-agcc.com, jekotrade.com, jindianglass.net, glenheadpowerequipment.com, wallofportfolios.com, bopcon.com, resoto.com, wagnerdavis.com, ramcolab.com, explosystems.com, wecastnetworkinc.com, gdheyin.com, boyu-group.com, fiyanoventures.com, carleaseusa.com, theinnotech.net, jobsync.com.au, wisehousetech.com, cloudflare.net, hotelaquamarsandiego.com, qd-baolian.com, csofam.com, gatorchucks.cn, co.com, swiss-architects.com, avocaresources.com.au, zmc.com.sa, innfos.cn, selecthealth.org, westernofficeplus.com, intermountainhealth.org, ss-web.com, baselinewoods.com, bestrun.net, jiabinnu.com, willcctv.com, bulgaria-offroad.com, alghanitex.com, cdjialu.com, qzz.io, birminghamneograft.com, aamhatch.com.au, organizeyourlife.com.au, era.sa, dehuiguangchang.cn, xjgudao.com, kfstock.com, gatsbylabs.com, bobc.com.tw, faradai.ai, porcelainchina.net, intermountainnv.org, brownsprinting.com, delichemical.com, cloudhq-mkt6.net, garyjackson.com, detcrc.com.au, cyberpowersystems.com.tw, hzhsyr.com, aboveandbeyondcleaningservices.com, kblmining.com.au, mamuz.at, cclvcr.com, swiftfreightlogistics.com, anichemspeciality.com, klmymmyc.com, drillsearch.com.au, gydz.net, us.org, autoadvantage.com.au, gzfantai.net, bolinyinwu.net, totolink-shop.com, ceconstruction.com, hzjiaolun.com, hibetw.com, xweiying.com, hnbeixiang.com, sofibanque.com, chinayinshufood.com, harshpackers.in, xjjingyoga.com, gpchain.com, coronde.net, 1haojiyin.com, mubayyin.cn, kugler-installation.at, aibituo.net, tjwipes.net, framecoframing.com, philanthropynw.org, cofcohg.com, yongxinco.com, xjxhhydropower.com, detongwiremesh.com, jlhhzy.com, www.us.com, dldianfeng.cn, intermountainhealthcare.org, gaithersburgflorist.com, dgclh.com, bamko.net, ausarabbusinesscouncil.com, hansecontrol.com, lstcarbon.com, gryphonminerals.com.au, ttstest.com, lamaxwell.com, housing.gov.sa, gaetanasnyc.com, apo-led.com, esolutions.sa, bnw163.net, yhjgkeji.com, ebonyshemalevideos.com, beiyuecheng.com, knlpropertymanagement.com, cshczfz.com, epckorealtd.com, www.eu.com, dogsparesort.com, hongyang0769.net, xeraliving.fi, gzshengjie56.com, jssd.net, eu.org, bierte.com, yangjiangshilimaoyi.com, qldtradeprint.com.au, pesasybalanzas.com, dreamacquisition.com, com.de, ttyt360.com, www.de.com, healthoz.com.au, kalaifashions.com, seemine.net, ssindustriesindia.com, hygroup.net, shinruey.net, basis.org, zgkaite.com, turnoutservices.com, jollysocks.com, 0991df.net, szlis.com.cn, vulcantowing.com, northstarind.com, zjdddl.com, m-wood2.com, factoringexpress.com, gaoyimall.net, nesp.com, dslawn.com, shoppingninja.com.au, xjnmi.com, ljgyp.net, szsbs.net, intellectsoft.net, willamettevalleyhd.com, oracle-ag.ch, zjhrbz.com, fzfortune.net, livingdreams.net, sddyhy.net, neumann-group.com, allkaz.com, univance.com, bereaace.com, laytonclinic.org, 869606.com, mark1airforce.com, bain86.com, caviton.com, mzmistelbach.at, cmedicagalerias.pt, wenpow.com, carbonenergy.com.au, workers.dev, geowash.com.au, hashemfoods.com, dublincleaningservices.com, whzn.net, navissupply.com, prnewswire.com, playtechretail.com, ecodirect.com.au, cnkejie.com, woodrowetreetech.com.au, resgen.com.au, 8189330.cn, tigerexpressfuel.com, jinpac.com, cfgt18.com, tdh.org, movemegroup.com.au, charlottecommerce.com, co.zm, sglcfj.com, nationalspecialties.net, pollyholding.com, anhuaabrasives.net, playtech.com, nethive.com, avantemarine.com.au, puravidaenergy.com.au, nacionalpedras.com, importandexportspecializedequipmentandservicesinc.com, impresosmonterrey.com, shworldbest.com, ronhooverboats.com, gemcats.com, liyubelt.net.cn, dongguansenzi.com, spinintel.com, carmaxbolivia.com, ckxoh.com, fyinn.net, sosdevelopment.com.au, rockrobotic.com, lassocountry.com, condevconstruction.com.au, priborenergogas.ru, memorytrainingcenters.com, unicornmgt.com, interlinkcargo.com.br, magmametals.com.au, cswafc.com.au, eneabbagas.com.au, chinakangtai.net, northerncomforthvac.com, finalhit.com, lutheranmedicalcenter.org, imail.org, geochem.org, icms.net.au, gomarinegroup.com.au, knowledgepartners.com.au, octagon.studio, prosci.com.au |
| 112.114.202.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Yunnan | 28/08/2026, 01:25:01 | 01/09/2026, 15:01:08 | - | - | - | - | - | - |
| 1.92.73.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 28/08/2026, 01:25:01 | 09/09/2026, 01:13:38 | Yes | No | - | CVE-2023-44487, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 03:37:02 | smartcom.cc, huawei.com, huaweidevice.com |
| 106.81.36.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | Chinanet Chongqing | 28/08/2026, 01:25:01 | 28/08/2026, 08:29:38 | No | No | - | - | 22/08/2026, 03:37:03 | - |
| 159.75.243.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 28/08/2026, 01:25:00 | 09/09/2026, 13:59:12 | No | No | - | CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-7347 | 28/08/2026, 03:37:09 | - |
| 167.86.88.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS51167 | Contabo GmbH | Contabo | 28/08/2026, 01:23:05 | 30/08/2026, 01:22:50 | Yes | Yes | APT14, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT40, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Equation Group, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, UNC2452, Volt Typhoon, WIRTE | CVE-2006-20001, CVE-2016-20012, CVE-2017-15710, CVE-2017-15715, CVE-2017-15906, CVE-2017-3167, CVE-2017-3169, CVE-2017-7659, CVE-2017-7668, CVE-2017-7679, CVE-2017-9788, CVE-2017-9798, CVE-2018-11763, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312, CVE-2018-1333, CVE-2018-15473, CVE-2018-15919, CVE-2018-17189, CVE-2018-17199, CVE-2018-20685, CVE-2019-0196, CVE-2019-0197, CVE-2019-0211, CVE-2019-0217, CVE-2019-0220, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2019-9517, CVE-2020-11993, CVE-2020-13938, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-26690, CVE-2021-26691, CVE-2021-33193, CVE-2021-34798, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-45802, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24795, CVE-2024-27316, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-26465, CVE-2025-32728, CVE-2025-49812, CVE-2025-53020 | 28/08/2026, 02:08:06 | contaboserver.net, contabo.de, contabo.net |
| 18.162.239.•••:18789 | - | 🇭🇰 Hong Kong | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Hong Kong | 28/08/2026, 01:23:05 | 30/08/2026, 01:22:50 | No | - | - | - | 22/08/2026, 02:08:07 | - |
| 192.84.39.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS31898 | Oracle Corporation | Network Solutions | 28/08/2026, 01:23:05 | 30/08/2026, 01:22:50 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 02:08:08 | domainnamebidder.com, hostmonster.com, unifiedlayer.com, site5.com, domain.com, dot5hosting.com, readyhosting.com, homestead.com, mojomarketplace.com, bizland.com, powweb.com, newfold.com, webhost4life.com, web.com, dotster.com, bluehost.com |
| 104.207.88.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS22612 | Namecheap, Inc. | Namecheap | 28/08/2026, 01:23:05 | 02/09/2026, 03:50:25 | - | - | - | - | - | - |
| 142.215.36.•••:18789 | - | 🇺🇸 United States | - | true | Leaked | AS15830 | Equinix (EMEA) Acquisition Enterprises B.V. | Equinix | 28/08/2026, 01:23:05 | 10/09/2026, 11:54:29 | Yes | No | - | - | 28/08/2026, 02:08:11 | equinix.hk, pihana.com, equinix.in, gaohongidc.cn, equinix.com, equinix.kr, equinix.fi, equinix.ae, equinix.lat, equinix.cn, equinix.fr, cmsw.com, q9.com, layerone.com, equinix.sg |
| 47.108.105.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 28/08/2026, 01:23:05 | 10/09/2026, 11:54:51 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-1695 | 28/08/2026, 02:08:13 | - |
| 34.104.134.•••:18789 | Assistant | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 28/08/2026, 00:46:27 | 10/09/2026, 12:01:15 | No | No | - | CVE-2016-20012, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 09:20:44 | - | |
| 3.249.126.•••:443 | - | 🇮🇪 Ireland | Yes | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Data Services Ireland | 28/08/2026, 00:46:26 | 28/08/2026, 12:04:56 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6110, CVE-2020-14145 | 28/08/2026, 10:43:01 | - |
| 47.84.81.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 28/08/2026, 00:46:24 | 10/09/2026, 12:00:38 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 05:43:52 | hichina.com, alibaba-inc.com |
| 16.78.91.•••:443 | - | 🇸🇬 Singapore | Yes | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Jakarta | 28/08/2026, 00:46:24 | 28/08/2026, 12:47:19 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 05:43:56 | - |
| 31.173.148.•••:18789 | - | 🇷🇺 Russia | - | false | Clean | AS31133 | PJSC MegaFon | MegaFon | 28/08/2026, 00:44:39 | 28/08/2026, 06:24:51 | Yes | Yes | APT35 | CVE-2016-20012, CVE-2018-5740, CVE-2018-5741, CVE-2018-5743, CVE-2018-5744, CVE-2018-5745, CVE-2019-6465, CVE-2019-6470, CVE-2019-6471, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2020-8616, CVE-2020-8617, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624, CVE-2020-8625, CVE-2021-25214, CVE-2021-25215, CVE-2021-25216, CVE-2021-25219, CVE-2021-25220, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2022-2795, CVE-2022-38177, CVE-2022-38178, CVE-2023-2828, CVE-2023-2829, CVE-2023-2911, CVE-2023-3341, CVE-2023-4236, CVE-2023-4408, CVE-2023-50387, CVE-2023-5517, CVE-2023-5679, CVE-2023-5680, CVE-2024-0760, CVE-2024-11187, CVE-2024-12705, CVE-2024-1737, CVE-2024-1975, CVE-2024-4076, CVE-2025-13878, CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 | 28/08/2026, 02:14:08 | indusoft.ru |
| 34.104.134.•••:18789 | Assistant | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 28/08/2026, 00:44:38 | 10/09/2026, 07:02:16 | No | No | - | CVE-2016-20012, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 02:14:15 | - | |
| 3.249.126.•••:18789 | - | 🇮🇪 Ireland | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon Data Services Ireland | 28/08/2026, 00:44:36 | 28/08/2026, 06:24:49 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6110, CVE-2020-14145 | 28/08/2026, 05:00:51 | - |
| 47.84.81.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 28/08/2026, 00:44:33 | 10/09/2026, 11:59:02 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 05:01:00 | hichina.com, alibaba-inc.com |
| 34.104.134.•••:18789 | Assistant | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 28/08/2026, 00:42:39 | 10/09/2026, 09:07:48 | No | No | - | CVE-2016-20012, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 00:45:57 | - | |
| 104.248.224.•••:18789 | - | 🇺🇸 United States | - | false | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 28/08/2026, 00:40:42 | 30/08/2026, 00:40:23 | No | Yes | APT14, APT17, APT28, APT35, APT36, APT37, APT39, APT40, APT41, APT45, CloudSorcerer, Cobalt Group, Daggerfly APT, Equation Group, Gamaredon Group, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Sandworm Team, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, UNC2452, WIRTE | CVE-2006-20001, CVE-2016-20012, CVE-2017-15710, CVE-2017-15715, CVE-2018-11763, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312, CVE-2018-1333, CVE-2018-15473, CVE-2018-15919, CVE-2018-17189, CVE-2018-17199, CVE-2018-20685, CVE-2019-0196, CVE-2019-0197, CVE-2019-0211, CVE-2019-0217, CVE-2019-0220, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2019-9517, CVE-2020-11993, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-26690, CVE-2021-26691, CVE-2021-28041, CVE-2021-33193, CVE-2021-34798, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/08/2026, 02:08:02 | - |
| 107.175.189.•••:80 | - | 🇺🇸 United States | Yes | true | Leaked | AS36352 | HostPapa | HostPapa | 28/08/2026, 00:04:23 | 06/09/2026, 01:02:59 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10002, CVE-2016-10003, CVE-2016-20012, CVE-2017-15906, CVE-2018-1000024, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-12519, CVE-2019-12521, CVE-2019-12523, CVE-2019-12525, CVE-2019-12526, CVE-2019-12529, CVE-2019-16905, CVE-2019-18676, CVE-2019-18677, CVE-2019-18678, CVE-2019-18679, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-11945, CVE-2020-14058, CVE-2020-14145, CVE-2020-15049, CVE-2020-15778, CVE-2020-25097, CVE-2021-28041, CVE-2021-28651, CVE-2021-31807, CVE-2021-36368, CVE-2021-41617, CVE-2021-46784, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 07:54:50 | hostpapa.com |
| 60.220.163.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | Changzhi Lichengju IP Pool | 28/08/2026, 00:04:23 | 28/08/2026, 11:22:36 | No | No | - | - | 22/08/2026, 07:54:53 | - |
| 197.79.60.•••:18789 | - | 🇿🇦 South Africa | Yes | false | Clean | AS37611 | AFRIHOST SP | African Network Information Centre | 28/08/2026, 00:04:23 | 28/08/2026, 11:22:36 | No | No | - | - | 22/08/2026, 07:54:59 | - |
| 103.236.91.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS134768 | CHINANET SHAANXI province Cloud Base network | Sichuan Xiaoteyun Technology | 28/08/2026, 00:04:23 | 31/08/2026, 21:05:42 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/08/2026, 07:55:10 | cnnic.cn |
| 183.23.62.•••:9107 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | CHINANET Guangdong | 28/08/2026, 00:04:22 | 31/08/2026, 14:29:56 | Yes | No | - | CVE-2011-2716, CVE-2011-5325, CVE-2013-1813, CVE-2014-9645, CVE-2015-9261, CVE-2016-2147, CVE-2016-2148, CVE-2016-6301, CVE-2017-16544, CVE-2018-1000500, CVE-2018-1000517, CVE-2018-20679, CVE-2019-14834, CVE-2019-5747, CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687, CVE-2021-3448, CVE-2022-0934, CVE-2022-28391, CVE-2022-48174, CVE-2023-28450, CVE-2023-50387, CVE-2024-58251, CVE-2025-46394, CVE-2025-60876 | 28/08/2026, 07:55:14 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 114.132.82.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 28/08/2026, 00:04:21 | 31/08/2026, 12:23:57 | Yes | Yes | APT37, El-Machete | - | 28/08/2026, 09:20:20 | tencentcloud.com |
| 46.62.246.•••:443 | - | 🇫🇮 Finland | Yes | false | Leaked | AS24940 | Hetzner Online GmbH | Hetzner | 28/08/2026, 00:04:21 | 31/08/2026, 22:30:02 | Yes | No | - | CVE-2023-38709, CVE-2024-24795, CVE-2024-27316, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-55753, CVE-2025-58098, CVE-2025-59775, CVE-2025-61984, CVE-2025-61985, CVE-2025-65082, CVE-2025-66200, CVE-2026-24072, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 09:20:21 | hetzner.com |
| 107.175.189.•••:18789 | - | 🇺🇸 United States | - | true | Leaked | AS36352 | HostPapa | HostPapa | 28/08/2026, 00:02:32 | 05/09/2026, 20:02:12 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10002, CVE-2016-10003, CVE-2016-20012, CVE-2017-15906, CVE-2018-1000024, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-12519, CVE-2019-12521, CVE-2019-12523, CVE-2019-12525, CVE-2019-12526, CVE-2019-12529, CVE-2019-16905, CVE-2019-18676, CVE-2019-18677, CVE-2019-18678, CVE-2019-18679, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-11945, CVE-2020-14058, CVE-2020-14145, CVE-2020-15049, CVE-2020-15778, CVE-2020-25097, CVE-2021-28041, CVE-2021-28651, CVE-2021-31807, CVE-2021-36368, CVE-2021-41617, CVE-2021-46784, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | 28/08/2026, 02:13:11 | hostpapa.com |