General Information

Submitter Diversity: Low
Risk (0-10)details: 0
RESEARCHER: THIS IP IS USED FOR INTERNET WIDE RESEARCH SCANS
IP Address (click for more detail): 2.59.22.234
Hostname: red3.census.shodan.io
Country:  CA
ASN: 12989
AS Name:  BlackHOST - Black HOST Ltd, CA
Network:  2.59.22.0/24 (2.59.22.0-2.59.22.255) 2.59.23.0
Reports:  - none -
Targets:  - none -
First Reported: N/A
Most Recent Report: N/A
Comment: - none -
Abuse Contact for AS12989: [email protected]
Links to articles about the IP from rosti.bin.re

Note: We update the data once an hour. To refresh the data, click here. Not all source IPs in our database are "attackers". There are a few common false positives. For example, hosts that participate in P2P networks, mail servers, load balancers and DNS servers are some of the most common issues. For details, click on the number of reports. Clicking on the number of reports may allow you to conclude if a report is a false positive or not. Scroll down for information from other data feeds.

SSH/Telnet Logs

no ssh logs.

Web Honeypot Logs

Date Reports Different URLs Different User Agents
2026-05-28963
2026-05-27632
2026-05-26953
2026-05-251664
2026-05-24963
2026-05-23823
2026-05-22663
2026-05-211232
2026-05-201863
2026-05-192063
2026-05-181333
2026-05-17663
2026-05-162563
2026-05-15663

For more details about the web honeypot, see the Weblogs Page. Do not use these reports to identify IP addresses as "bad" for now.

External Threat Feeds

This data was retrieved from various external data feeds.

First Seen Last Seen Feed
2025-03-222026-09-28Port 22 Scanner
2025-02-282026-09-28Port 25 Scanner
2025-02-272026-09-28CI Army List
2025-06-032026-09-28ShodanHQ
Check Threatstop for more data link arrow