🦞 OpenClaw Exposure Watchboard
This page lists publicly reachable active OpenClaw instances for defensive awareness. If this is your deployment, enable authentication, remove direct public exposure, and patch immediately.
Exposed Instances: 1076720 Page: 2225 / 10768 (100 per page) Showing: 222401-222500 Last Imported: 10/09/2026, 14:51:48
🇨🇳 507,651
🇺🇸 312,129
Build With Vivgrid
Explore Vivgrid Ship Secure Enterprise AI Agents 10× Faster with vivgrid.com
Vivgrid gives you authentication, model gateway, tool control, cost tracking, and enterprise observability — everything you need to ship AI agents safely at scale.
| Endpoint | Assistant Name | Country | auth_required | is_active | has_leaked_creds | asn | asn_name | org | first_seen | last_seen | asi_has_breach | asi_has_threat_actor | asi_threat_actors | asi_cves | asi_enriched_at | asi_domains |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 117.72.205.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS141679 | China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch | JD.com | 22/05/2026, 01:13:47 | 03/06/2026, 14:03:56 | Yes | No | - | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 24/05/2026, 21:57:35 | jdl.cn, vackbot.com, vg.com, jdfinance.com, 51buy.com, blackdragon.com, jddj.com, 7fresh.com, jd.com, 360buy.com, chinabank.com.cn, 360buyimg.com, imdada.cn, jdh.com |
| 60.20.33.•••:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom Liaoning | 22/05/2026, 01:13:47 | 22/05/2026, 08:16:29 | - | - | - | - | - | - |
| 47.253.244.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud US | 22/05/2026, 01:13:47 | 10/09/2026, 11:58:48 | No | No | - | - | 22/05/2026, 00:46:49 | - |
| 180.126.228.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4134 | Chinanet | Chinanet Jiangsu Province Network | 22/05/2026, 01:13:47 | 31/05/2026, 00:06:03 | Yes | No | - | - | 30/05/2026, 21:20:40 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 140.245.30.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS31898 | Oracle Corporation | Oracle | 22/05/2026, 01:13:47 | 18/08/2026, 15:47:11 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 29/05/2026, 15:00:22 | healtheintent.com, purewellness.com, cerner.ae, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, healtheatcerner.com, oracle.com, hiedirectconnect.org, maxymiser.net, oraclecloudservices.com, rsys2.net, hyperroll.com, nor1.com, oxygen.systems, oraclegovcloud.com, orcale.com, oraclemobile.com, sun.co.in, openair.co, oraclepdemos.com, stellent.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, mvalent.com, netsuitesuiteprojectspro.com, elementfusion.com, netsuiteforms.com, oraclecloud.com, en25.com, solaris.com, rightnowtech.com, think.com, ipapp.com, jdedwards.com, tiger-institute.org, zenedge.com, skire.com, sun.com, ateam-oracle.com, sales.com, fyleio.com, push.io, estara.com, tekelec.com, textura.com, paymyhealthbill.com, dyndns.com, java.net, optika.com, jcp.org, smed.com, cernerenviza-tw.com, datafox.com, recruitmax.com, decisioneering.com, adiinsights.com, stortek.com, seebeyond.com, livelook.com, openjdk.org, virtualbox.org, dyn.com, oraclehealth.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com, oracledatacloud.com |
| 106.55.173.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:13:47 | 07/06/2026, 13:09:17 | Yes | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-7347, CVE-2025-23419 | 29/05/2026, 09:20:15 | tencent.com |
| 118.31.165.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:13:47 | 08/09/2026, 12:21:20 | Yes | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617 | 28/05/2026, 12:43:21 | aliyun.com |
| 27.14.255.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS4837 | CHINA UNICOM China169 Backbone | China Unicom Chongqing | 22/05/2026, 01:13:47 | 28/05/2026, 07:02:49 | Yes | No | - | - | 25/05/2026, 07:48:06 | chinaunicom.cn |
| 39.98.90.•••:18789 | - | 🇨🇳 China mainland | - | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:13:47 | 04/06/2026, 19:25:19 | Yes | No | - | - | 01/06/2026, 05:31:25 | aliyun.com |
| 64.90.4.•••:18789 | - | 🇭🇰 Hong Kong | - | true | Clean | AS979 | NetLab Global | NetLab Global | 22/05/2026, 01:13:47 | 09/09/2026, 11:09:52 | No | No | - | - | 29/05/2026, 22:26:04 | - |
| 217.142.235.•••:18789 | - | 🇺🇸 United States | - | false | Leaked | AS31898 | Oracle Corporation | Oracle Sweden | 22/05/2026, 01:13:47 | 09/06/2026, 09:36:51 | Yes | Yes | APT29, APT34, Carbanak, MuddyWater Group, TA456 | CVE-2016-2124, CVE-2017-11103, CVE-2017-12150, CVE-2017-12151, CVE-2017-12163, CVE-2017-14746, CVE-2017-15275, CVE-2017-7494, CVE-2018-1050, CVE-2018-1057, CVE-2018-10858, CVE-2018-10919, CVE-2018-14628, CVE-2018-14629, CVE-2018-16841, CVE-2018-16851, CVE-2019-10218, CVE-2019-14833, CVE-2019-14847, CVE-2019-14861, CVE-2019-14870, CVE-2019-14902, CVE-2019-3824, CVE-2019-3880, CVE-2020-10704, CVE-2020-10730, CVE-2020-10745, CVE-2020-10760, CVE-2020-14318, CVE-2020-14323, CVE-2020-14383, CVE-2020-1472, CVE-2020-17049, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719, CVE-2020-25722, CVE-2020-27840, CVE-2021-20251, CVE-2021-20254, CVE-2021-20277, CVE-2021-20316, CVE-2021-3670, CVE-2021-3671, CVE-2021-3738, CVE-2021-43566, CVE-2021-44141, CVE-2021-44142, CVE-2022-0336, CVE-2022-1615, CVE-2022-2031, CVE-2022-26691, CVE-2022-32742, CVE-2022-32743, CVE-2022-32744, CVE-2022-32746, CVE-2022-3437, CVE-2022-37966, CVE-2022-37967, CVE-2022-38023, CVE-2022-42898, CVE-2022-45141, CVE-2023-0614, CVE-2023-0922, CVE-2023-28531, CVE-2023-34966, CVE-2023-34967, CVE-2023-34968, CVE-2023-38408, CVE-2023-3961, CVE-2023-4091, CVE-2023-4154, CVE-2023-42669, CVE-2023-42670, CVE-2023-46118, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-5568, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 31/05/2026, 18:19:04 | healtheintent.com, purewellness.com, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, healtheatcerner.com, oraclecloudservices.com, rsys2.net, hyperroll.com, orcale.com, oraclemobile.com, sun.co.in, stellent.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, mvalent.com, netsuitesuiteprojectspro.com, elementfusion.com, oracleemaildelivery.com, en25.com, solaris.com, rightnowtech.com, think.com, ipapp.com, jdedwards.com, tiger-institute.org, skire.com, ateam-oracle.com, sales.com, fyleio.com, push.io, estara.com, tekelec.com, textura.com, paymyhealthbill.com, dyndns.com, optika.com, jcp.org, smed.com, cernerenviza-tw.com, recruitmax.com, decisioneering.com, stortek.com, seebeyond.com, livelook.com, oraclehealth.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com |
| 35.160.154.•••:18789 | - | 🇺🇸 United States | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:12:00 | 22/05/2026, 07:32:05 | - | - | - | - | - | - |
| 114.116.233.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 22/05/2026, 01:12:00 | 31/05/2026, 18:56:10 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 25/05/2026, 11:18:35 | smartcom.cc, huawei.com, huaweidevice.com |
| 45.33.94.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS63949 | Akamai Connected Cloud | Linode | 22/05/2026, 01:12:00 | 08/09/2026, 13:03:28 | No | No | - | CVE-2016-20012, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728 | 25/05/2026, 07:04:16 | - |
| 186.240.23.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS132839 | POWER LINE DATACENTER | HK Powerline | 22/05/2026, 01:12:00 | 31/05/2026, 15:26:20 | - | - | - | - | - | - |
| 54.236.60.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS14618 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:12:00 | 25/05/2026, 05:37:37 | - | - | - | - | - | - |
| 198.252.101.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS59253 | LEASEWEB SINGAPORE PTE. LTD. | Hawk Host | 22/05/2026, 01:12:00 | 08/09/2026, 22:23:05 | No | Yes | APT14, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT40, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Earth Berberoka, Equation Group, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, UNC2452, Volt Typhoon, WIRTE | CVE-2006-20001, CVE-2013-1896, CVE-2013-4352, CVE-2013-5704, CVE-2013-6438, CVE-2014-0098, CVE-2014-0117, CVE-2014-0118, CVE-2014-0226, CVE-2014-0231, CVE-2014-3523, CVE-2014-3581, CVE-2014-8109, CVE-2015-0228, CVE-2015-3183, CVE-2015-3185, CVE-2016-0736, CVE-2016-10708, CVE-2016-20012, CVE-2016-2161, CVE-2016-4975, CVE-2016-5387, CVE-2016-8612, CVE-2016-8743, CVE-2017-15710, CVE-2017-15715, CVE-2017-15906, CVE-2017-3167, CVE-2017-7679, CVE-2017-9788, CVE-2017-9798, CVE-2018-1283, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2018-1312, CVE-2018-15473, CVE-2018-15919, CVE-2018-17199, CVE-2018-20685, CVE-2019-0217, CVE-2019-0220, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-11985, CVE-2020-13938, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-34798, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31628, CVE-2022-31629, CVE-2022-31630, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2022-37454, CVE-2023-25690, CVE-2023-28531, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-45802, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24795, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 29/05/2026, 00:47:12 | - |
| 154.203.124.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:12:00 | 08/09/2026, 11:36:22 | No | - | - | - | 24/05/2026, 02:19:09 | - |
| 136.175.83.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS209604 | -----BEGIN TOKEN-----386cceb8168a2bed7b3c259c9c055a81061dd7c33c124587c41110684a7636917f6d8b0d84f48ae3c5b89314076d2a06c92d6bfc6a0514e840a3a2c3f4cfa7bf-----END TOKEN----- | 2E Telecom | 22/05/2026, 01:12:00 | 10/09/2026, 11:57:11 | No | No | - | - | 28/06/2026, 15:45:06 | - |
| 38.6.46.•••:18789 | - | 🇨🇦 Canada | Yes | false | Clean | AS398993 | PEG TECH INC | Polyethylene Glycol-Lipid Association | 22/05/2026, 01:12:00 | 31/05/2026, 11:57:28 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 31/05/2026, 11:59:36 | - |
| 168.107.6.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS31898 | Oracle Corporation | Oracle | 22/05/2026, 01:12:00 | 28/06/2026, 01:42:35 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 24/05/2026, 02:16:54 | healtheintent.com, purewellness.com, cerner.ae, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, healtheatcerner.com, oracle.com, hiedirectconnect.org, maxymiser.net, oraclecloudservices.com, rsys2.net, hyperroll.com, nor1.com, oxygen.systems, oraclegovcloud.com, orcale.com, oraclemobile.com, sun.co.in, openair.co, oraclepdemos.com, stellent.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, mvalent.com, netsuitesuiteprojectspro.com, elementfusion.com, netsuiteforms.com, oraclecloud.com, en25.com, solaris.com, rightnowtech.com, think.com, ipapp.com, jdedwards.com, tiger-institute.org, zenedge.com, skire.com, sun.com, ateam-oracle.com, sales.com, fyleio.com, push.io, estara.com, tekelec.com, textura.com, paymyhealthbill.com, dyndns.com, java.net, optika.com, jcp.org, smed.com, cernerenviza-tw.com, datafox.com, recruitmax.com, decisioneering.com, adiinsights.com, stortek.com, seebeyond.com, livelook.com, openjdk.org, virtualbox.org, dyn.com, oraclehealth.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com, oracledatacloud.com |
| 139.199.89.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:12:00 | 10/09/2026, 11:57:06 | - | - | - | - | - | - |
| 39.98.167.•••:18789 | - | 🇨🇳 China mainland | - | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:12:00 | 08/09/2026, 15:13:21 | Yes | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 25/05/2026, 07:06:40 | aliyun.com |
| 113.44.49.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS55990 | Huawei Cloud Service data center | Huawei Cloud | 22/05/2026, 01:12:00 | 03/08/2026, 14:04:55 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 03/06/2026, 12:40:48 | smartcom.cc, huawei.com, huaweidevice.com |
| 157.180.113.•••:18789 | - | 🇫🇮 Finland | Yes | false | Leaked | AS24940 | Hetzner Online GmbH | Hetzner | 22/05/2026, 01:12:00 | 30/06/2026, 11:33:43 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 26/05/2026, 12:01:41 | hetzner.com |
| 39.98.72.•••:18789 | - | 🇨🇳 China mainland | - | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:12:00 | 03/06/2026, 11:11:55 | Yes | Yes | APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, Volt Typhoon, WIRTE | CVE-2006-20001, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-9517, CVE-2020-11984, CVE-2020-11993, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-39275, CVE-2021-40438, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-27522, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387 | 28/05/2026, 02:49:20 | aliyun.com |
| 207.126.167.•••:18789 | - | 🇺🇸 United States | - | false | Clean | AS36007 | Kamatera, Inc. | Kamatera US LA | 22/05/2026, 01:12:00 | 22/05/2026, 11:45:43 | No | No | - | - | 16/05/2026, 11:08:13 | - |
| 2408:823d:4c17:3aa0:8ac9:b3ff:feb4:1b6b:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom | 22/05/2026, 01:12:00 | 22/05/2026, 07:32:04 | - | - | - | - | - | - |
| 152.42.237.•••:18789 | - | 🇸🇬 Singapore | Yes | false | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 22/05/2026, 01:11:59 | 15/07/2026, 16:29:10 | No | Yes | APT-C-23, APT15, APT17, APT28, APT31, APT36, APT37, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Ghostwriter, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, RomCom Group, Salt Typhoon, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2021-23017, CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 25/05/2026, 12:42:32 | - |
| 50.6.243.•••:18789 | - | 🇺🇸 United States | - | false | Leaked | AS31898 | Oracle Corporation | Newfold Digital | 22/05/2026, 01:11:59 | 05/07/2026, 04:32:38 | Yes | No | - | - | 06/06/2026, 13:13:48 | athenixinc.com, hostmonster.com, site5.com, domain.com, readyhosting.com, homestead.com, endurance.com, mojomarketplace.com, mybluehost.me, dotster.com, bluehost.com |
| 34.205.26.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS14618 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:11:59 | 22/05/2026, 07:32:04 | - | - | - | - | - | - |
| 2a02:4780:5e:b9e8::1:18789 | - | 🇲🇾 Malaysia | - | false | Clean | AS47583 | Hostinger International Limited | Hostinger | 22/05/2026, 01:11:59 | 05/08/2026, 20:22:11 | - | - | - | - | - | - |
| 13.204.238.•••:18789 | - | 🇮🇳 India | - | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:11:59 | 09/09/2026, 18:13:06 | No | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 22/05/2026, 08:59:45 | - |
| 43.205.68.•••:18789 | - | 🇮🇳 India | - | false | Clean | AS16509 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:11:59 | 12/08/2026, 19:14:13 | No | - | - | - | 19/05/2026, 04:15:58 | - |
| 156.234.13.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | Yancy Limited | 22/05/2026, 01:11:59 | 08/09/2026, 05:54:18 | No | No | - | - | 25/05/2026, 13:21:29 | - |
| 117.72.217.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS141679 | China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch | JD.com | 22/05/2026, 01:11:59 | 25/08/2026, 05:26:39 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 31/05/2026, 13:21:49 | jdl.cn, vackbot.com, vg.com, jdfinance.com, 51buy.com, blackdragon.com, jddj.com, 7fresh.com, jd.com, 360buy.com, chinabank.com.cn, 360buyimg.com, imdada.cn, jdh.com |
| 124.222.106.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:11:59 | 26/05/2026, 04:16:59 | - | - | - | - | - | - |
| 34.136.51.•••:18789 | Assistant | 🇺🇸 United States | Yes | false | Clean | AS396982 | Google LLC | 22/05/2026, 01:11:59 | 30/05/2026, 19:09:27 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, DragonFly, Kimsuky, Mustang Panda, Packrat, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 28/05/2026, 04:55:05 | - | |
| 162.243.122.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 22/05/2026, 01:11:59 | 10/09/2026, 10:32:11 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728 | 27/05/2026, 21:09:34 | - |
| 81.70.254.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 22/05/2026, 01:11:59 | 20/06/2026, 08:56:52 | No | Yes | APT37, El-Machete, Sandworm Team | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2020-8616, CVE-2020-8617, CVE-2020-8618, CVE-2020-8619, CVE-2020-8620, CVE-2020-8621, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624, CVE-2020-8625, CVE-2021-25214, CVE-2021-25215, CVE-2021-25216, CVE-2021-25219, CVE-2021-25220, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2022-2795, CVE-2022-3094, CVE-2022-38177, CVE-2022-38178 | 02/06/2026, 20:26:41 | - |
| 201.189.201.•••:18789 | - | 🇨🇱 Chile | Yes | false | Clean | AS7418 | TELEFÓNICA CHILE S.A. | Telefonica Movil de Chile | 22/05/2026, 01:11:59 | 28/05/2026, 07:01:00 | No | No | - | - | 22/05/2026, 06:22:01 | - |
| 119.4.53.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom Sichuan | 22/05/2026, 01:11:59 | 25/05/2026, 08:27:01 | - | - | - | - | - | - |
| 94.131.94.•••:18789 | - | 🇰🇿 Kazakhstan | Yes | false | Clean | AS208795 | "Cloud Services Kazakhstan" LLP | Yandex Cloud | 22/05/2026, 01:11:59 | 22/05/2026, 07:32:04 | - | - | - | - | - | - |
| 144.229.28.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS11404 | Wave Broadband | Rackdog | 22/05/2026, 01:11:59 | 06/06/2026, 21:37:20 | Yes | Yes | APT15, APT31, Bitter APT, Bluenoroff, Donot Team, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, Salt Typhoon, SideWinder APT | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 24/05/2026, 21:13:09 | cogentco.com |
| 124.221.46.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:11:59 | 21/07/2026, 12:52:20 | Yes | No | - | CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 22/05/2026, 18:49:33 | tencent.com |
| 186.240.115.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS132839 | POWER LINE DATACENTER | HK Powerline | 22/05/2026, 01:11:59 | 26/07/2026, 16:51:07 | No | No | - | - | 19/05/2026, 08:28:13 | - |
| 156.247.106.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Octopus Web Solution Inc | 22/05/2026, 01:11:59 | 10/09/2026, 11:56:38 | No | No | - | CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 25/05/2026, 08:27:57 | - |
| 62.238.16.•••:18789 | - | 🇫🇮 Finland | Yes | false | Leaked | AS24940 | Hetzner Online GmbH | Hetzner Online | 22/05/2026, 01:11:59 | 14/07/2026, 23:12:35 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 06/06/2026, 06:55:09 | hetzner.com |
| 47.237.64.•••:18789 | - | 🇺🇸 United States | - | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 22/05/2026, 01:11:59 | 10/09/2026, 10:32:13 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 31/05/2026, 21:47:44 | hichina.com, alibaba-inc.com |
| 47.237.165.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 22/05/2026, 01:11:59 | 08/09/2026, 14:30:06 | Yes | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387 | 24/05/2026, 21:13:00 | hichina.com, alibaba-inc.com |
| 213.165.50.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS210644 | AEZA GROUP LLC | Netcrafters | 22/05/2026, 01:11:58 | 31/05/2026, 16:08:09 | No | No | - | CVE-2023-44487, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 31/05/2026, 15:30:09 | - |
| 149.202.59.•••:18789 | - | 🇫🇷 France | Yes | false | Leaked | AS16276 | OVH SAS | OVH | 22/05/2026, 01:11:58 | 31/05/2026, 15:26:18 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 25/05/2026, 12:01:02 | ovh.net |
| 43.103.52.•••:18789 | - | 🇸🇬 Singapore | - | false | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud Singapore | 22/05/2026, 01:11:58 | 05/07/2026, 20:55:54 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 03/06/2026, 16:11:02 | alibabacloud.com |
| 154.203.124.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:11:58 | 09/09/2026, 11:08:05 | No | No | - | - | 22/05/2026, 11:59:11 | - |
| 47.76.176.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 22/05/2026, 01:11:58 | 01/06/2026, 10:26:39 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 26/05/2026, 00:48:23 | - |
| 8.136.58.•••:18789 | - | 🇸🇬 Singapore | Yes | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alibaba Cloud | 22/05/2026, 01:11:58 | 29/05/2026, 18:32:27 | No | No | - | - | 19/05/2026, 09:53:46 | - |
| 204.168.209.•••:18789 | - | 🇫🇮 Finland | Yes | true | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 22/05/2026, 01:11:58 | 09/09/2026, 23:10:13 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 29/05/2026, 02:11:42 | duckdns.org |
| 14.103.82.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS137718 | Beijing Volcano Engine Technology Co., Ltd. / AS4811 China Telecom (Group) | Beijing Volcano Engine Technology | 22/05/2026, 01:11:58 | 09/09/2026, 05:28:26 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 30/05/2026, 09:24:17 | bytedance.com |
| 89.208.252.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS25820 | IT7 Networks Inc / AS8126 Cloud Fabric, Inc. | IT7 Networks | 22/05/2026, 01:11:58 | 05/07/2026, 02:24:06 | Yes | - | - | CVE-2021-23017, CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 26/05/2026, 14:06:21 | 16clouds.com |
| 103.41.5.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | 111 Sports West | 22/05/2026, 01:11:58 | 10/09/2026, 11:56:32 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, DragonFly, El-Machete, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 25/05/2026, 08:28:28 | - |
| 45.130.215.•••:18789 | - | 🇱🇻 Latvia | Yes | false | Clean | AS9002 | RETN Limited | Beget LLC | 22/05/2026, 01:11:58 | 26/07/2026, 18:59:17 | No | - | - | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 27/05/2026, 17:36:55 | - |
| 91.99.163.•••:18789 | - | 🇩🇪 Germany | - | false | Leaked | AS24940 | Hetzner Online GmbH | Hetzner Online | 22/05/2026, 01:11:58 | 16/06/2026, 16:53:38 | Yes | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 28/05/2026, 11:59:38 | hetzner.com |
| 47.92.243.•••:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:58 | 02/06/2026, 14:34:14 | - | - | - | - | - | - |
| 38.6.9.•••:18789 | - | 🇯🇵 Japan | Yes | false | Clean | AS398993 | PEG TECH INC | Polyethylene Glycol-Lipid Association | 22/05/2026, 01:11:58 | 31/05/2026, 04:58:24 | No | Yes | APT28, APT29, APT35, APT37, APT39, APT41, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2014-0160, CVE-2014-0224, CVE-2014-1692, CVE-2014-2532, CVE-2014-2653, CVE-2015-10003, CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2016-0777, CVE-2016-0778, CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 27/05/2026, 19:01:19 | - |
| 117.50.152.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS23724 | IDC, China Telecommunications Corporation / AS4808 China Unicom Beijing Province Network | UCloud | 22/05/2026, 01:11:58 | 09/09/2026, 21:44:33 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 25/05/2026, 12:44:27 | ucloud.cn |
| 45.151.31.•••:18789 | - | 🇷🇺 Russia | Yes | false | Clean | AS208677 | "Cloud Technologies" LLC trading as Cloud.ru | Cloud.ru | 22/05/2026, 01:11:58 | 18/08/2026, 11:23:57 | Yes | Yes | APT15, APT17, APT28, APT31, APT36, APT37, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, RomCom Group, Salt Typhoon, Sea Turtle Group, SideWinder APT, The Shadow Brokers | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/05/2026, 09:12:02 | cloudtech.ie |
| 203.209.212.•••:18789 | - | 🇦🇺 Australia | - | false | Clean | AS133480 | 5G NETWORK OPERATIONS PTY LTD | 5G Network Operations | 22/05/2026, 01:11:58 | 22/05/2026, 07:32:03 | - | - | - | - | - | - |
| 156.252.33.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:11:58 | 01/07/2026, 10:32:02 | No | No | - | - | 19/05/2026, 04:16:21 | - |
| 2a02:4780:f:5f7d::1:18789 | - | 🇬🇧 United Kingdom | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 22/05/2026, 01:11:58 | 09/09/2026, 21:44:29 | - | - | - | - | - | - |
| 45.10.208.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS132839 | POWER LINE DATACENTER | Hong Kong Power Line | 22/05/2026, 01:11:58 | 31/05/2026, 00:04:13 | - | - | - | - | - | - |
| 154.205.86.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:11:58 | 15/07/2026, 08:32:38 | No | No | - | - | 21/05/2026, 09:08:32 | - |
| 118.178.224.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:58 | 24/07/2026, 07:11:54 | Yes | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 03/06/2026, 11:54:43 | aliyun.com, zjol.com.cn, thehour.cn |
| 38.6.18.•••:18789 | - | 🇯🇵 Japan | Yes | false | Clean | AS398993 | PEG TECH INC | Polyethylene Glycol-Lipid Association | 22/05/2026, 01:11:58 | 29/05/2026, 11:22:42 | No | No | - | - | 23/05/2026, 10:43:47 | - |
| 154.205.84.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:11:58 | 16/07/2026, 03:17:03 | No | - | - | - | 19/05/2026, 04:16:03 | - |
| 47.107.103.•••:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:58 | 12/06/2026, 20:21:25 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/05/2026, 09:10:47 | - |
| 39.106.186.•••:18789 | - | 🇽🇽 XX | Yes | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Unknown | 22/05/2026, 01:11:57 | 05/08/2026, 02:30:45 | Yes | No | - | - | 27/05/2026, 20:24:39 | aliyun.com |
| 66.228.37.•••:18789 | - | 🇺🇸 United States | - | false | Clean | AS63949 | Akamai Connected Cloud | Linode | 22/05/2026, 01:11:57 | 09/08/2026, 15:51:20 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Carbanak, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, Lyceum APT, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, TA505, TEMP.Hermit, The Shadow Brokers, Volt Typhoon | CVE-2015-5352, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2015-8325, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-1908, CVE-2016-20012, CVE-2016-3115, CVE-2016-6210, CVE-2016-6515, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 29/06/2026, 10:29:25 | duckdns.org |
| 47.92.28.•••:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:57 | 24/07/2026, 19:20:05 | No | No | - | - | 28/05/2026, 22:42:47 | - |
| 159.194.221.•••:18789 | - | 🇷🇺 Russia | Yes | false | Clean | AS198610 | Beget LLC | Beget LLC | 22/05/2026, 01:11:57 | 12/06/2026, 04:50:42 | No | No | - | - | 31/05/2026, 06:54:15 | - |
| 47.101.71.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:57 | 08/09/2026, 12:19:16 | No | No | - | - | 22/05/2026, 00:00:58 | - |
| 77.93.152.•••:18789 | - | 🇺🇸 United States | Yes | false | Clean | AS401479 | Database Mart LLC | Private Customer | 22/05/2026, 01:11:57 | 06/07/2026, 04:46:30 | No | - | - | CVE-2023-46724, CVE-2023-46728, CVE-2023-46846, CVE-2023-46847, CVE-2023-46848, CVE-2023-49285, CVE-2023-49286, CVE-2023-49288, CVE-2023-50269, CVE-2023-5824, CVE-2024-23638, CVE-2024-25111, CVE-2024-25617, CVE-2024-33427, CVE-2024-37894 | 30/05/2026, 12:53:07 | - |
| 178.104.239.•••:18789 | - | 🇩🇪 Germany | Yes | false | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 22/05/2026, 01:11:57 | 25/06/2026, 01:29:50 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 24/05/2026, 23:20:16 | - |
| 2a02:4780:41:46f8::1:18789 | - | 🇩🇪 Germany | - | false | Clean | AS47583 | Hostinger International Limited | Hostinger | 22/05/2026, 01:11:57 | 12/06/2026, 17:32:21 | - | - | - | - | - | - |
| 47.253.194.•••:18789 | - | 🇨🇳 China mainland | - | false | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud US | 22/05/2026, 01:11:57 | 16/08/2026, 09:18:06 | No | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 24/05/2026, 19:04:00 | - |
| 122.51.222.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:11:57 | 10/09/2026, 04:09:23 | Yes | Yes | APT37, El-Machete | - | 03/06/2026, 04:12:15 | tencent.com, tencentcloud.com |
| 121.50.36.•••:18789 | - | 🇮🇩 Indonesia | Yes | false | Clean | AS38750 | Telemedia Dinamika Sarana, PT | Telemedia Dinamika Sarana | 22/05/2026, 01:11:57 | 08/07/2026, 06:12:15 | No | No | - | - | 22/05/2026, 17:01:17 | - |
| 219.151.183.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS134420 | Chongqing Telecom | ChinaNet Chongqing | 22/05/2026, 01:11:57 | 07/09/2026, 19:56:13 | No | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 31/05/2026, 12:01:02 | - |
| 23.235.180.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS138415 | Yancy Limited | RedLuff | 22/05/2026, 01:11:57 | 08/09/2026, 13:47:28 | No | Yes | Packrat | - | 27/05/2026, 17:37:15 | - |
| 156.234.27.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS138415 | Yancy Limited | Yancy Limited | 22/05/2026, 01:11:57 | 10/09/2026, 01:18:44 | No | No | - | - | 21/05/2026, 22:33:53 | - |
| 47.253.137.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud US | 22/05/2026, 01:11:57 | 09/09/2026, 07:35:54 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 25/05/2026, 07:04:40 | - |
| 2a02:4780:75:b009::1:18789 | - | 🇺🇸 United States | - | false | Clean | AS47583 | Hostinger International Limited | Hostinger | 22/05/2026, 01:11:57 | 25/05/2026, 01:24:04 | - | - | - | - | - | - |
| 2a02:c207:2308:4942::1:18789 | - | 🇫🇷 France | - | false | Clean | AS51167 | Contabo GmbH | Contabo | 22/05/2026, 01:11:57 | 04/07/2026, 22:51:09 | - | - | - | - | - | - |
| 156.252.34.•••:18789 | - | 🇭🇰 Hong Kong | Yes | false | Clean | AS9294 | GNET INC. | Cloud Innovation | 22/05/2026, 01:11:57 | 29/06/2026, 06:52:52 | No | No | - | - | 27/05/2026, 06:46:49 | - |
| 104.244.94.•••:18789 | - | 🇺🇸 United States | Yes | false | Leaked | AS25820 | IT7 Networks Inc | IT7 Networks | 22/05/2026, 01:11:57 | 08/07/2026, 18:18:48 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | 06/06/2026, 18:49:36 | 16clouds.com |
| 27.112.79.•••:18789 | - | 🇮🇩 Indonesia | Yes | false | Clean | AS136052 | PT Cloud Hosting Indonesia | IDCloudHost | 22/05/2026, 01:11:57 | 07/06/2026, 06:06:19 | No | Yes | APT-C-23, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, Equation Group, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2021-23017, CVE-2021-3618, CVE-2022-41741, CVE-2022-41742, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 28/05/2026, 01:25:47 | - |
| 42.193.201.•••:18789 | - | 🇨🇳 China mainland | Yes | false | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 22/05/2026, 01:11:57 | 31/05/2026, 00:46:10 | Yes | Yes | APT37, El-Machete | - | 23/05/2026, 20:41:34 | tencent.com |
| 54.233.34.•••:18789 | - | 🇧🇷 Brazil | - | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Brazil | 22/05/2026, 01:11:57 | 09/09/2026, 07:35:51 | No | No | - | CVE-2023-38709, CVE-2024-24795, CVE-2024-27316, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-55753, CVE-2025-58098, CVE-2025-59775, CVE-2025-65082, CVE-2025-66200 | 22/05/2026, 17:23:39 | - |
| 39.106.20.•••:18789 | - | 🇽🇽 XX | - | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Unknown | 22/05/2026, 01:11:57 | 24/05/2026, 23:59:44 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-1695 | 24/05/2026, 19:04:17 | aliyun.com |
| 16.58.71.•••:18789 | - | 🇺🇸 United States | - | false | Leaked | AS16509 | Amazon.com, Inc. | Amazon | 22/05/2026, 01:11:57 | 28/05/2026, 12:38:51 | Yes | No | - | CVE-2006-20001, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-27522, CVE-2023-31122, CVE-2023-38709, CVE-2023-45802, CVE-2024-24795, CVE-2024-27316, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-55753, CVE-2025-58098, CVE-2025-59775, CVE-2025-65082, CVE-2025-66200 | 25/05/2026, 02:52:30 | bookworm.com, lovefilm.com, amazon.eu, amazaon.com, z-exp.com, shopbop.com, accept.com, amazonn.com, boxofficemojo.com, amazonaws-us-gov.com, amaozn.com, awsamazon.com, amazonmusiclocal.com, a9.com, amzzon.com, mturk.com, com.be, amazonpay.com, rooftopmedia.net, vine.com, amazon.com.au, amazon-rings.com, amazonin.com, amzn.asia, apn-portal.com, evi.com, amazonprime.com, audiblecareers.com, beautybar.com, permit.io, junglee.com, tenmarks.com, amazonwebservices.net, associates-amazon.com, amazonrobotics.com, endless.com, amazonlocal.com, amazonllc.com, media-imdb.com, amazon.com.tw, amazonaws.com, kivasystems.com, amzn.com, amazon.com, thinkboxsoftware.com |
| 39.98.63.•••:18789 | - | 🇨🇳 China mainland | - | false | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 22/05/2026, 01:11:57 | 03/06/2026, 12:36:39 | Yes | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Turla APT Group, Volt Typhoon | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2020-8022, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 31/05/2026, 07:47:36 | aliyun.com |