🦞 OpenClaw Exposure Watchboard
This page lists publicly reachable active OpenClaw instances for defensive awareness. If this is your deployment, enable authentication, remove direct public exposure, and patch immediately.
Exposed Instances: 926582 Page: 749 / 9266 (100 per page) Showing: 74801-74900 Last Imported: 07/06/2026, 03:36:56
🇨🇳 458,280
🇺🇸 265,401
Build With Vivgrid
Explore Vivgrid Ship Secure Enterprise AI Agents 10× Faster with vivgrid.com
Vivgrid gives you authentication, model gateway, tool control, cost tracking, and enterprise observability — everything you need to ship AI agents safely at scale.
| Endpoint | Assistant Name | Country | auth_required | is_active | has_leaked_creds | asn | asn_name | org | first_seen | last_seen | asi_has_breach | asi_has_threat_actor | asi_threat_actors | asi_cves | asi_enriched_at | asi_domains |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 45.192.98.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS401701 | cognetcloud INC | Vapeline Technology | 21/05/2026, 22:27:25 | 01/06/2026, 08:25:06 | No | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 06:58:03 | - |
| 5.78.205.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS212317 | Hetzner Online GmbH | Hetzner | 21/05/2026, 22:27:25 | 06/06/2026, 11:10:19 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:04 | hetzner.com |
| 168.144.122.•••:18789 | - | 🇮🇳 India | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:25 | 06/06/2026, 16:04:29 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 03/06/2026, 12:00:34 | - |
| 14.103.59.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS137718 | Beijing Volcano Engine Technology Co., Ltd. / AS4811 China Telecom (Group) | Beijing Volcano Engine Technology | 21/05/2026, 22:27:25 | 06/06/2026, 23:48:21 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:09 | bytedance.com |
| 52.79.201.•••:443 | - | 🇰🇷 South Korea | Yes | true | Clean | AS16509 | Amazon.com, Inc. | AWS Seoul Region | 21/05/2026, 22:27:25 | 05/06/2026, 23:13:21 | No | Yes | APT14, APT40, APT41, Gamaredon Group, Kimsuky, Lazarus Group, SharpPanda | CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2021-44224, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943 | 22/05/2026, 06:58:10 | - |
| 134.199.166.•••:443 | - | 🇦🇺 Australia | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:25 | 06/06/2026, 19:34:57 | No | No | - | CVE-2016-20012, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:12 | - |
| 156.252.34.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 21/05/2026, 22:27:25 | 06/06/2026, 09:04:12 | No | No | - | - | 16/05/2026, 06:58:13 | - |
| 64.90.0.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS979 | NetLab Global | NetLab Global | 21/05/2026, 22:27:25 | 22/05/2026, 07:36:26 | - | - | - | - | - | - |
| 186.240.22.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS132839 | POWER LINE DATACENTER | HK Powerline | 21/05/2026, 22:27:25 | 30/05/2026, 19:55:34 | No | No | - | - | 16/05/2026, 06:58:17 | - |
| 164.90.239.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:24 | 05/06/2026, 07:36:03 | No | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-7347, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 06:58:18 | - |
| 103.191.92.•••:18789 | - | 🇮🇩 Indonesia | Yes | true | Clean | AS136052 | PT Cloud Hosting Indonesia | PT Maju Bersama Tepat Guna | 21/05/2026, 22:27:24 | 04/06/2026, 14:22:55 | No | No | - | - | 16/05/2026, 06:58:20 | - |
| 15.217.110.•••:443 | - | 🇪🇸 Spain | Yes | true | Leaked | AS16509 | Amazon.com, Inc. | Amazon Data Services Spain | 21/05/2026, 22:27:24 | 06/06/2026, 12:34:02 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 03/06/2026, 16:18:04 | bookworm.com, lovefilm.com, shopbop.com, boxofficemojo.com, amaozn.com, com.be, amazonpay.com, amzn.asia, associates-amazon.com, endless.com, amazonaws.com, amazon.com |
| 2a02:4780:75:4573::1:18789 | - | 🇺🇸 United States | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 21/05/2026, 22:27:24 | 04/06/2026, 03:44:01 | - | - | - | - | - | - |
| 103.73.190.•••:11019 | - | 🇮🇳 India | Yes | true | Clean | AS135752 | Evoke Digital Solutions | Evoke Digital Solutions | 21/05/2026, 22:27:24 | 06/06/2026, 16:04:29 | Yes | No | - | - | 22/05/2026, 06:58:24 | evokedigital.in |
| 44.202.77.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS14618 | Amazon.com, Inc. | Amazon Web Services | 21/05/2026, 22:27:24 | 07/06/2026, 00:30:06 | No | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:26 | - |
| 103.41.6.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | 111 Sports West | 21/05/2026, 22:27:24 | 06/06/2026, 13:58:11 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, DragonFly, El-Machete, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 22/05/2026, 06:58:27 | - |
| 46.225.160.•••:80 | - | 🇩🇪 Germany | Yes | true | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 21/05/2026, 22:27:24 | 05/06/2026, 18:58:00 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:29 | - |
| 202.155.94.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138115 | PT Deneva | PT Imtel Sinerigi Utama | 21/05/2026, 22:27:24 | 06/06/2026, 11:10:23 | Yes | No | - | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:30 | cyberassets.ae |
| 45.76.207.•••:443 | - | 🇯🇵 Japan | Yes | true | Leaked | AS20473 | The Constant Company, LLC | Vultr Holdings | 21/05/2026, 22:27:24 | 06/06/2026, 17:28:32 | Yes | Yes | DragonFly, Salt Typhoon | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:31 | vultr.com |
| 39.97.245.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:24 | 07/06/2026, 01:11:26 | Yes | No | - | CVE-2024-7347, CVE-2025-23419 | 22/05/2026, 06:58:33 | aliyun.com |
| 180.113.166.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | Chinanet Jiangsu Province Network | 21/05/2026, 22:27:24 | 22/05/2026, 07:36:25 | Yes | No | - | - | 22/05/2026, 07:42:36 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 185.23.35.•••:18789 | - | 🇷🇺 Russia | Yes | true | Clean | AS198610 | Beget LLC | Beget LLC | 21/05/2026, 22:27:24 | 05/06/2026, 12:33:06 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 07:42:38 | - |
| 156.247.109.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Octopus Web Solution Inc | 21/05/2026, 22:27:24 | 06/06/2026, 21:41:27 | No | No | - | CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 22/05/2026, 06:58:35 | - |
| 43.133.26.•••:443 | - | 🇯🇵 Japan | Yes | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 21/05/2026, 22:27:24 | 06/06/2026, 13:58:10 | Yes | Yes | APT15, APT17, APT28, APT31, APT35, APT36, APT37, APT39, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:37 | tencent.com |
| 20.253.143.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 21/05/2026, 22:27:24 | 06/06/2026, 23:48:22 | No | No | - | - | 16/05/2026, 06:58:40 | - |
| 142.171.227.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS35916 | MULTACOM CORPORATION | Multacom Corporation | 21/05/2026, 22:27:24 | 05/06/2026, 20:23:13 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2020-14145, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:41 | mytelus.com, globetrotter.qc.ca, telusassyst.com, telus.net, multacom.com, telusdigital.com, telusquebec.com, radiant.net, globetrotter.net, telus.ca, koodomobile.com, storyhive.com, graydonsecurity.com, telus.com, telusplanet.net, telus.digital, telus.org, telushealth.co |
| 81.71.129.•••:80 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 21/05/2026, 22:27:24 | 06/06/2026, 17:28:36 | No | Yes | APT37, El-Machete | - | 22/05/2026, 06:58:43 | - |
| 195.26.255.•••:18789 | - | 🇩🇪 Germany | Yes | false | Leaked | AS40021 | Contabo Inc. | Contabo | 21/05/2026, 22:27:24 | 25/05/2026, 11:20:07 | Yes | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT36, APT37, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 06:58:45 | contabo.de, contabo.net |
| 185.170.144.•••:443 | - | 🇬🇪 Georgia | Yes | true | Clean | AS50053 | VDSka hosting | [name redacted] | 21/05/2026, 22:27:24 | 06/06/2026, 13:16:01 | No | No | - | CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 03/06/2026, 02:19:37 | - |
| 103.236.53.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS4816 | China Telecom (Group) | Shenzhen Yunshang Wuyou Network Technology | 21/05/2026, 22:27:24 | 06/06/2026, 19:35:00 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 06:58:47 | eu.org |
| 216.22.13.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS30633 | Leaseweb USA, Inc. | Leaseweb USA | 21/05/2026, 22:27:24 | 06/06/2026, 02:03:09 | Yes | No | - | - | 22/05/2026, 06:58:48 | leaseweb.com, ubiquityhosting.com |
| 192.3.63.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS36352 | HostPapa | Network Next | 21/05/2026, 22:27:24 | 06/06/2026, 14:40:15 | No | Yes | APT17, APT36, APT37, APT45, CloudSorcerer, Daggerfly APT, Kimsuky, MuddyWater Group, SideWinder APT, The Shadow Brokers | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 06:58:50 | - |
| 101.43.6.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 21/05/2026, 22:27:24 | 06/06/2026, 03:27:10 | Yes | Yes | APT37, El-Machete | - | 22/05/2026, 06:58:52 | tencent.com |
| 34.46.181.•••:80 | - | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 21/05/2026, 22:27:24 | 31/05/2026, 09:14:17 | No | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728 | 22/05/2026, 06:58:53 | - | |
| 121.41.200.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:24 | 06/06/2026, 11:10:21 | - | - | - | - | - | - |
| 113.31.105.•••:80 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS17621 | China Unicom Shanghai network / AS4811 China Telecom (Group) | UCloud | 21/05/2026, 22:27:24 | 06/06/2026, 09:04:11 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT37, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 22/05/2026, 06:58:56 | ucloud.cn |
| 103.85.227.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS401696 | cognetcloud INC | I Layer Limited | 21/05/2026, 22:27:24 | 05/06/2026, 14:40:51 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:27:25 | - |
| 178.104.201.•••:18789 | - | 🇩🇪 Germany | Yes | false | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 21/05/2026, 22:27:24 | 28/05/2026, 18:29:12 | - | - | - | - | - | - |
| 24.144.90.•••:443 | Assistant | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:24 | 06/06/2026, 08:21:43 | No | Yes | APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2006-20001, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-27522, CVE-2023-28531, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-45802, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24795, CVE-2024-27316, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:27 | - |
| 125.92.107.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS136199 | CHINANET Guangdong province Yuedong MAN network | CHINANET Guangdong | 21/05/2026, 22:27:24 | 22/05/2026, 07:36:24 | Yes | - | - | - | 21/05/2026, 22:27:31 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 14.103.71.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS137718 | Beijing Volcano Engine Technology Co., Ltd. / AS4811 China Telecom (Group) | Beijing Volcano Engine Technology | 21/05/2026, 22:27:24 | 05/06/2026, 11:50:26 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:32 | bytedance.com |
| 47.92.99.•••:50001 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:23 | 03/06/2026, 03:32:14 | No | No | - | - | 15/05/2026, 22:27:33 | - |
| 82.156.235.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 21/05/2026, 22:27:23 | 05/06/2026, 23:56:09 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, El-Machete, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 21/05/2026, 22:27:35 | - |
| 137.184.160.•••:443 | - | 🇨🇦 Canada | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:23 | 06/06/2026, 13:16:00 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:36 | - |
| 47.116.193.•••:6020 | - | 🇨🇳 China mainland | Yes | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:23 | 24/05/2026, 19:51:03 | No | - | - | - | 15/05/2026, 22:27:39 | - |
| 160.202.254.•••:15001 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS146817 | Hubei Feixun Network Co., Ltd | Hubei Feixun Network | 21/05/2026, 22:27:23 | 27/05/2026, 18:22:01 | Yes | No | - | CVE-2019-14834, CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687, CVE-2021-3448, CVE-2022-0934, CVE-2023-28450, CVE-2023-50387 | 21/05/2026, 22:27:41 | qzz.io |
| 142.171.163.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS35916 | MULTACOM CORPORATION | Multacom Corporation | 21/05/2026, 22:27:23 | 25/05/2026, 07:48:53 | Yes | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT36, APT37, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2024-7347, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:42 | mytelus.com, globetrotter.qc.ca, telusassyst.com, telus.net, multacom.com, telusdigital.com, telusquebec.com, radiant.net, globetrotter.net, telus.ca, koodomobile.com, storyhive.com, graydonsecurity.com, telus.com, telusplanet.net, telus.digital, telus.org, telushealth.co |
| 8.211.145.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud Singapore | 21/05/2026, 22:27:23 | 06/06/2026, 13:16:03 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2024-6484, CVE-2024-6485, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:27:43 | eu.org |
| 103.39.18.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS138415 | Yancy Limited | RedLuff | 21/05/2026, 22:27:23 | 04/06/2026, 12:15:33 | No | Yes | APT28, APT40, Energetic Bear, Equation Group, Leafminer, Luckycat APT | CVE-2010-1899, CVE-2010-2730, CVE-2010-3972 | 21/05/2026, 22:27:44 | - |
| 156.234.226.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | Yancy Limited | 21/05/2026, 22:27:23 | 06/06/2026, 06:15:26 | No | No | - | - | 15/05/2026, 22:27:46 | - |
| 89.167.54.•••:18789 | - | 🇫🇮 Finland | Yes | true | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 21/05/2026, 22:27:23 | 05/06/2026, 21:48:28 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:27:49 | - |
| 85.215.211.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS8560 | This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE. | IONOS | 21/05/2026, 22:27:23 | 05/06/2026, 16:07:02 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:50 | profitbricks.com, pbiaas.com |
| 116.205.242.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 21/05/2026, 22:27:23 | 06/06/2026, 15:22:26 | Yes | Yes | APT14, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT40, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Equation Group, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, UNC2452, Volt Typhoon, WIRTE | CVE-2006-20001, CVE-2014-9767, CVE-2015-8994, CVE-2016-0736, CVE-2016-20012, CVE-2016-2161, CVE-2016-4975, CVE-2016-5387, CVE-2016-7478, CVE-2016-8612, CVE-2016-8740, CVE-2016-8743, CVE-2017-15710, CVE-2017-15715, CVE-2017-15906, CVE-2017-3167, CVE-2017-3169, CVE-2017-7679, CVE-2017-9788, CVE-2017-9798, CVE-2018-11763, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312, CVE-2018-1333, CVE-2018-15473, CVE-2018-15919, CVE-2018-17189, CVE-2018-17199, CVE-2018-19520, CVE-2018-20685, CVE-2019-0196, CVE-2019-0211, CVE-2019-0217, CVE-2019-0220, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2019-9517, CVE-2020-11984, CVE-2020-11985, CVE-2020-11993, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:27:51 | smartcom.cc, huawei.com, huaweidevice.com |
| 82.202.157.•••:9000 | - | 🇷🇺 Russia | Yes | true | Clean | AS208677 | "Cloud Technologies" LLC trading as Cloud.ru | Cloud.ru | 21/05/2026, 22:27:23 | 07/06/2026, 01:11:55 | Yes | No | - | - | 03/06/2026, 18:28:45 | cloudtech.ie |
| 49.232.203.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 21/05/2026, 22:27:23 | 30/05/2026, 14:19:16 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385 | 21/05/2026, 22:27:55 | tencent.com |
| 182.92.108.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:23 | 27/05/2026, 22:38:43 | Yes | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 21/05/2026, 22:27:56 | aliyun.com, talefun.com |
| 34.50.96.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 21/05/2026, 22:27:23 | 06/06/2026, 03:27:12 | No | No | - | - | 15/05/2026, 22:27:58 | - | |
| 163.7.8.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Leaked | AS150436 | Byteplus Pte. Ltd. | Byteplus | 21/05/2026, 22:27:23 | 06/06/2026, 17:28:34 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:27:59 | bytedance.com |
| 154.12.30.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS401696 | cognetcloud INC | FOJ IP Technology | 21/05/2026, 22:27:23 | 06/06/2026, 06:15:30 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 21/05/2026, 22:28:01 | cogentco.com |
| 173.249.38.•••:443 | - | 🇩🇪 Germany | Yes | true | Leaked | AS51167 | Contabo GmbH | Contabo | 21/05/2026, 22:27:23 | 05/06/2026, 12:33:03 | Yes | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728 | 21/05/2026, 22:28:02 | contaboserver.net, contabo.de, contabo.net |
| 47.92.93.•••:50001 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:23 | 03/06/2026, 19:49:59 | No | Yes | APT-C-23, Gamaredon Group, Ghostwriter, Lazarus Group, Turla APT Group, Volt Typhoon | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:03 | - |
| 140.245.45.•••:443 | - | 🇺🇸 United States | Yes | true | Leaked | AS31898 | Oracle Corporation | Oracle | 21/05/2026, 22:27:23 | 06/06/2026, 13:16:01 | Yes | Yes | APT15, APT17, APT28, APT31, APT36, APT37, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, RomCom Group, Salt Typhoon, Sea Turtle Group, SideWinder APT, The Shadow Brokers | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:28:05 | healtheintent.com, purewellness.com, cerner.ae, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, healtheatcerner.com, oracle.com, hiedirectconnect.org, maxymiser.net, oraclecloudservices.com, rsys2.net, hyperroll.com, nor1.com, oxygen.systems, oraclegovcloud.com, orcale.com, oraclemobile.com, sun.co.in, openair.co, oraclepdemos.com, stellent.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, mvalent.com, netsuitesuiteprojectspro.com, elementfusion.com, netsuiteforms.com, oraclecloud.com, en25.com, solaris.com, rightnowtech.com, think.com, ipapp.com, jdedwards.com, tiger-institute.org, zenedge.com, skire.com, sun.com, ateam-oracle.com, sales.com, fyleio.com, push.io, estara.com, tekelec.com, textura.com, paymyhealthbill.com, dyndns.com, java.net, optika.com, jcp.org, smed.com, cernerenviza-tw.com, datafox.com, recruitmax.com, decisioneering.com, adiinsights.com, stortek.com, seebeyond.com, livelook.com, openjdk.org, virtualbox.org, dyn.com, oraclehealth.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com, oracledatacloud.com |
| 139.59.224.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:23 | 06/06/2026, 07:39:41 | No | Yes | APT-C-23, APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, Equation Group, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, Turla APT Group, UNC2452, Volt Typhoon, WIRTE | CVE-2016-20012, CVE-2019-17567, CVE-2020-11984, CVE-2020-11993, CVE-2020-12062, CVE-2020-13950, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-23017, CVE-2021-26690, CVE-2021-26691, CVE-2021-28041, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-3618, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813, CVE-2022-41741, CVE-2022-41742, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:06 | - |
| 38.6.18.•••:443 | - | 🇯🇵 Japan | Yes | true | Clean | AS398993 | PEG TECH INC | Polyethylene Glycol-Lipid Association | 21/05/2026, 22:27:23 | 31/05/2026, 01:32:18 | No | No | - | - | 15/05/2026, 22:28:07 | - |
| 132.243.113.•••:18789 | - | 🇦🇪 United Arab Emirates | Yes | false | Clean | AS216154 | CLODO CLOUD SERVICE CO. L.L.C | Clodo Cloud Service | 21/05/2026, 22:27:23 | 25/05/2026, 13:29:17 | - | - | - | - | - | - |
| 199.255.99.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS35916 | MULTACOM CORPORATION | CloudCone | 21/05/2026, 22:27:23 | 06/06/2026, 20:59:17 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:12 | - |
| 154.205.85.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 21/05/2026, 22:27:22 | 06/06/2026, 13:58:15 | No | - | - | - | 15/05/2026, 22:28:13 | - |
| 47.245.60.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud Japan | 21/05/2026, 22:27:22 | 06/06/2026, 13:58:16 | No | - | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:28:14 | - |
| 43.129.174.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 21/05/2026, 22:27:22 | 05/06/2026, 11:50:26 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 21/05/2026, 22:28:15 | tencent.com |
| 44.247.91.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 21/05/2026, 22:27:22 | 02/06/2026, 22:37:19 | No | No | - | - | 15/05/2026, 22:28:16 | - |
| 62.234.55.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 21/05/2026, 22:27:22 | 06/06/2026, 05:33:11 | No | Yes | APT-C-23, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387 | 21/05/2026, 22:28:17 | - |
| 129.211.209.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 21/05/2026, 22:27:22 | 04/06/2026, 07:17:58 | No | Yes | APT37, El-Machete | - | 21/05/2026, 22:28:21 | - |
| 154.205.83.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 21/05/2026, 22:27:22 | 06/06/2026, 06:57:47 | No | - | - | - | 15/05/2026, 22:28:23 | - |
| 43.201.57.•••:443 | - | 🇰🇷 South Korea | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 21/05/2026, 22:27:22 | 06/06/2026, 18:10:52 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2023-38709, CVE-2024-24795, CVE-2024-27316, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-55753, CVE-2025-58098, CVE-2025-59775, CVE-2025-65082, CVE-2025-66200 | 21/05/2026, 22:28:28 | - |
| 75.119.140.•••:18789 | - | 🇩🇪 Germany | Yes | false | Clean | AS51167 | Contabo GmbH | DirectPath | 21/05/2026, 22:27:22 | 25/05/2026, 14:56:36 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT36, APT37, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2018-19131, CVE-2018-19132, CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12523, CVE-2019-12524, CVE-2019-12525, CVE-2019-12526, CVE-2019-12527, CVE-2019-12528, CVE-2019-12529, CVE-2019-12854, CVE-2019-13345, CVE-2019-18676, CVE-2019-18677, CVE-2019-18678, CVE-2019-18679, CVE-2019-18860, CVE-2020-11945, CVE-2020-14058, CVE-2020-14145, CVE-2020-15049, CVE-2020-15778, CVE-2020-15810, CVE-2020-15811, CVE-2020-24606, CVE-2020-25097, CVE-2020-8449, CVE-2020-8450, CVE-2020-8517, CVE-2021-28041, CVE-2021-28116, CVE-2021-28651, CVE-2021-28652, CVE-2021-28662, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808, CVE-2021-33620, CVE-2021-36368, CVE-2021-41617, CVE-2021-46784, CVE-2022-41317, CVE-2022-41318, CVE-2023-28531, CVE-2023-38408, CVE-2023-46724, CVE-2023-46728, CVE-2023-46846, CVE-2023-46847, CVE-2023-48795, CVE-2023-49285, CVE-2023-49286, CVE-2023-49288, CVE-2023-50269, CVE-2023-51384, CVE-2023-51385, CVE-2023-5824, CVE-2024-25111, CVE-2024-25617, CVE-2024-33427, CVE-2024-37894, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:29 | - |
| 138.252.175.•••:18789 | - | 🇵🇰 Pakistan | Yes | true | Clean | AS154348 | Sky47 Limited | Sky47 Limited | 21/05/2026, 22:27:22 | 05/06/2026, 15:23:51 | No | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:31 | - |
| 8.130.213.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 21/05/2026, 22:27:22 | 06/06/2026, 11:51:58 | No | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:33 | - |
| 156.234.87.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | Yancy Limited | 21/05/2026, 22:27:22 | 05/06/2026, 23:56:06 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 21/05/2026, 22:28:34 | - |
| 122.231.210.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4134 | Chinanet | ChinaNet Hangzhou | 21/05/2026, 22:27:22 | 22/05/2026, 07:36:23 | No | No | - | - | 15/05/2026, 22:28:35 | - |
| 116.193.191.•••:18789 | - | 🇮🇩 Indonesia | Yes | true | Clean | AS136052 | PT Cloud Hosting Indonesia | IDCloudHost | 21/05/2026, 22:27:22 | 01/06/2026, 14:01:57 | Yes | No | - | CVE-2023-44487, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:37 | eu.org |
| 39.98.163.•••:50001 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:22 | 03/06/2026, 16:57:01 | Yes | Yes | Packrat | - | 21/05/2026, 22:28:38 | aliyun.com |
| 34.105.139.•••:18789 | Assistant | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 21/05/2026, 22:27:22 | 04/06/2026, 05:52:23 | No | Yes | DragonFly, Packrat | CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:41 | - | |
| 103.41.7.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | 111 Sports West | 21/05/2026, 22:27:22 | 05/06/2026, 20:23:12 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, DragonFly, El-Machete, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 21/05/2026, 22:28:43 | - |
| 2a02:4780:79:5d64::1:18789 | - | 🇩🇪 Germany | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 21/05/2026, 22:27:22 | 06/06/2026, 20:17:00 | - | - | - | - | - | - |
| 121.41.21.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:22 | 05/06/2026, 23:56:08 | Yes | No | - | - | 21/05/2026, 22:28:46 | aliyun.com |
| 102.134.34.•••:18789 | - | 🇹🇼 Taiwan | Yes | true | Clean | AS55933 | Cloudie Limited | Telkom SA | 21/05/2026, 22:27:22 | 06/06/2026, 11:10:22 | No | Yes | Packrat | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:28:48 | - |
| 2001:41d0:305:2100::6fda:18789 | - | 🇫🇷 France | - | true | Clean | AS16276 | OVH SAS | OVH | 21/05/2026, 22:27:22 | 05/06/2026, 23:13:21 | - | - | - | - | - | - |
| 194.233.90.•••:18789 | - | 🇸🇬 Singapore | Yes | false | Clean | AS141995 | Contabo Asia Private Limited | Contabo Asia Private Limited | 21/05/2026, 22:27:22 | 22/05/2026, 07:36:23 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:28:50 | - |
| 120.48.133.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS38365 | Beijing Baidu Netcom Science and Technology Co., Ltd. | Baidu | 21/05/2026, 22:27:22 | 06/06/2026, 20:17:03 | Yes | Yes | APT17, APT28, APT35, APT37, APT39, Cobalt Group, DragonFly, El-Machete, Gozi, Kimsuky, Mustang Panda, Packrat, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 21/05/2026, 22:28:51 | baidu.com |
| 16.148.226.•••:443 | - | 🇺🇸 United States | Yes | false | Leaked | AS16509 | Amazon.com, Inc. | Amazon | 21/05/2026, 22:27:22 | 30/05/2026, 05:10:35 | Yes | No | - | CVE-2016-10735, CVE-2018-14040, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-8331, CVE-2021-23017, CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-6484, CVE-2024-6485, CVE-2024-7347, CVE-2025-23419 | 21/05/2026, 22:28:52 | bookworm.com, healtheintent.com, purewellness.com, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, healtheatcerner.com, lovefilm.com, amazon.eu, oraclecloudservices.com, rsys2.net, amazaon.com, hyperroll.com, orcale.com, z-exp.com, oraclemobile.com, sun.co.in, stellent.com, shopbop.com, accept.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, amazonn.com, mvalent.com, boxofficemojo.com, amazonaws-us-gov.com, amaozn.com, awsamazon.com, netsuitesuiteprojectspro.com, amazonmusiclocal.com, cerner.com, elementfusion.com, a9.com, amzzon.com, mturk.com, en25.com, solaris.com, rightnowtech.com, think.com, com.be, ipapp.com, amazonpay.com, rooftopmedia.net, vine.com, amazon.com.au, amazon-rings.com, amazonin.com, jdedwards.com, amzn.asia, apn-portal.com, tiger-institute.org, skire.com, evi.com, ateam-oracle.com, sales.com, amazonprime.com, audiblecareers.com, fyleio.com, beautybar.com, push.io, estara.com, junglee.com, tekelec.com, textura.com, tenmarks.com, paymyhealthbill.com, dyndns.com, amazonwebservices.net, associates-amazon.com, optika.com, amazonrobotics.com, endless.com, amazonlocal.com, jcp.org, smed.com, cernerenviza-tw.com, recruitmax.com, decisioneering.com, stortek.com, amazonllc.com, seebeyond.com, media-imdb.com, amazon.com.tw, livelook.com, cernerworks.com, amazonaws.com, oraclehealth.com, kivasystems.com, amzn.com, amazon.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com, thinkboxsoftware.com |
| 104.207.139.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS20473 | The Constant Company, LLC | Vultr Holdings | 21/05/2026, 22:27:22 | 04/06/2026, 09:26:12 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:28:53 | vultr.com |
| 13.212.80.•••:443 | - | 🇸🇬 Singapore | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services | 21/05/2026, 22:27:22 | 07/06/2026, 00:30:46 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728 | 21/05/2026, 22:28:54 | - |
| 47.92.158.•••:50001 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:22 | 07/06/2026, 01:11:39 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-16905, CVE-2019-20372, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-23017, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51385, CVE-2024-7347, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 21/05/2026, 22:28:56 | - |
| 154.205.81.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 21/05/2026, 22:27:22 | 06/06/2026, 06:57:46 | No | No | - | - | 15/05/2026, 22:28:57 | - |
| 13.206.197.•••:18789 | - | 🇮🇳 India | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 21/05/2026, 22:27:22 | 05/06/2026, 22:30:52 | No | No | - | - | 30/05/2026, 18:58:25 | - |
| 101.200.149.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 21/05/2026, 22:27:22 | 05/06/2026, 13:58:16 | Yes | Yes | APT28, APT35, APT37, APT39, APT40, APT41, Cobalt Group, Earth Berberoka, Energetic Bear, Equation Group, Kimsuky, Leafminer, Luckycat APT, Mustang Panda, Sandworm Team | CVE-2010-1899, CVE-2010-2730, CVE-2010-3972, CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2018-15919, CVE-2020-14145, CVE-2021-41617, CVE-2023-31122, CVE-2023-38709, CVE-2023-43622, CVE-2023-45802, CVE-2024-24795, CVE-2024-27316, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573 | 21/05/2026, 22:28:59 | aliyun.com |
| 8.148.185.•••:443 | - | 🇸🇬 Singapore | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 21/05/2026, 22:27:22 | 06/06/2026, 12:34:05 | No | No | - | CVE-2016-10002, CVE-2016-10003, CVE-2018-1000024, CVE-2018-1000027, CVE-2018-19131, CVE-2018-19132, CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12523, CVE-2019-12524, CVE-2019-12525, CVE-2019-12526, CVE-2019-12528, CVE-2019-12529, CVE-2019-13345, CVE-2019-18676, CVE-2019-18677, CVE-2019-18678, CVE-2019-18679, CVE-2019-18860, CVE-2020-11945, CVE-2020-14058, CVE-2020-15049, CVE-2020-15810, CVE-2020-15811, CVE-2020-24606, CVE-2020-25097, CVE-2020-8449, CVE-2020-8450, CVE-2020-8517, CVE-2021-28116, CVE-2021-28651, CVE-2021-28652, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808, CVE-2021-33620, CVE-2021-46784, CVE-2022-41318, CVE-2023-46724, CVE-2023-46728, CVE-2023-46846, CVE-2023-46847, CVE-2023-49285, CVE-2023-49286, CVE-2023-49288, CVE-2023-50269, CVE-2023-5824, CVE-2024-25617, CVE-2024-33427, CVE-2024-37894, CVE-2024-45802, CVE-2025-54574 | 21/05/2026, 22:29:00 | - |
| 186.240.24.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS132839 | POWER LINE DATACENTER | HK Powerline | 21/05/2026, 22:27:22 | 31/05/2026, 16:12:08 | - | - | - | - | - | - |
| 42.194.202.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 21/05/2026, 22:27:22 | 22/05/2026, 07:36:22 | Yes | Yes | APT28, APT35, APT37, APT39, Cobalt Group, El-Machete, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 21/05/2026, 22:29:04 | tencent.com |
| 159.89.81.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 21/05/2026, 22:27:22 | 06/06/2026, 12:34:02 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 21/05/2026, 22:29:05 | - |