Last update: 2020-11-21

Host details

AS24940 Hetzner Online GmbH
Reported breaches

  • Port scan
% This is the RIPE Database query service.
% The objects are in RPSL format.
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to ' -'

% Abuse contact for ' -' is '[email protected]'

inetnum: -
netname:        DE-HETZNER-20090224
country:        FI
org:            ORG-HOA1-RIPE
admin-c:        HOAC1-RIPE
tech-c:         HOAC1-RIPE
status:         ALLOCATED PA
mnt-by:         RIPE-NCC-HM-MNT
mnt-by:         HOS-GUN
mnt-lower:      HOS-GUN
mnt-domains:    HOS-GUN
mnt-routes:     HOS-GUN
created:        2009-02-24T07:39:38Z
last-modified:  2017-11-02T11:54:31Z
source:         RIPE # Filtered

% Information related to ''

org:            ORG-HOA1-RIPE
descr:          HETZNER-DC
origin:         AS24940
mnt-by:         HOS-GUN
created:        2017-08-12T12:01:36Z
last-modified:  2018-01-10T08:47:33Z
source:         RIPE

% This query was served by the RIPE Database Query Service version 1.98 (WAGYU)

2 security incident(s) reported by users

BHD Honeypot
Port scan

In the last 24h, the attacker ( attempted to scan 1321 ports.
The following ports have been scanned: 3118/tcp (PKAgent), 3092/tcp, 3019/tcp (Resource Manager), 3005/tcp (Genius License Manager), 3205/tcp (iSNS Server Port), 3175/tcp (T1_E1_Over_IP), 3031/tcp (Remote AppleEvents/PPC Toolbox), 3136/tcp (Grub Server Port), 3081/tcp (TL1-LV), 3134/tcp (Extensible Code Protocol), 3398/tcp (Mercantile), 3123/tcp (EDI Translation Protocol), 3167/tcp (Now Contact Public Server), 3219/tcp (WMS Messenger), 3396/tcp (Printer Agent), 3358/tcp (Mp Sys Rmsvr), 3293/tcp (fg-fps), 3262/tcp (NECP), 3323/tcp, 3079/tcp (LV Front Panel), 3063/tcp (ncadg-ip-udp), 3216/tcp (Ferrari electronic FOAM), 3069/tcp (ls3), 3390/tcp (Distributed Service Coordinator), 3395/tcp (Dyna License Manager (Elam)), 3324/tcp, 3364/tcp (Creative Server), 3389/tcp (MS WBT Server), 3096/tcp (Active Print Server Port), 3127/tcp (CTX Bridge Port), 3265/tcp (Altav Tunnel), 3303/tcp (OP Session Client), 3317/tcp (VSAI PORT), 3012/tcp (Trusted Web Client), 3156/tcp (Indura Collector), 3356/tcp (UPNOTIFYPS), 3017/tcp (Event Listener), 3109/tcp (Personnel protocol), 3126/tcp, 3345/tcp (Influence), 3023/tcp (magicnotes), 3256/tcp (Compaq RPM Agent Port), 3195/tcp (Network Control Unit), 3213/tcp (NEON 24X7 Mission Control), 3344/tcp (BNT Manager), 3318/tcp (Swith to Swith Routing Information Protocol), 3107/tcp (Business protocol), 3161/tcp (DOC1 License Manager), 3158/tcp (SmashTV Protocol), 3050/tcp (gds_db), 3140/tcp (Arilia Multiplexor), 3236/tcp (appareNet Test Server), 3141/tcp (VMODEM), 3184/tcp (ApogeeX Port), 3257/tcp (Compaq RPM Server Port), 3124/tcp (Beacon Port), 3163/tcp (RES-SAP), 3363/tcp (NATI Vi Server), 3143/tcp (Sea View), 3144/tcp (Tarantella), 3105/tcp (Cardbox), 3044/tcp (EndPoint Protocol), 3202/tcp (IntraIntra), 3120/tcp (D2000 Webserver Port), 3100/tcp (OpCon/xps), 3061/tcp (cautcpd), 3104/tcp (Autocue Logger Protocol), 3330/tcp (MCS Calypso ICF), 3197/tcp (Embrace Device Protocol Server), 3215/tcp (JMQ Daemon Port 2), 3277/tcp (AWG Proxy), 3013/tcp (Gilat Sky Surfer), 3369/tcp, 3091/tcp (1Ci Server Management), 3187/tcp (Open Design Listen Port), 3159/tcp (NavegaWeb Tarification), 3075/tcp (Orbix 2000 Locator), 3077/tcp (Orbix 2000 Locator SSL), 3008/tcp (Midnight Technologies), 3214/tcp (JMQ Daemon Port 1), 3103/tcp (Autocue SMI Protocol), 3254/tcp (PDA System), 3339/tcp (OMF data l), 3029/tcp (LiebDevMgmt_A), 3151/tcp (NetMike Assessor), 3129/tcp (NetPort Discovery Port), 3315/tcp (CDID), 3288/tcp (COPS), 3224/tcp (AES Discovery Port), 3045/tcp (ResponseNet), 3267/tcp (IBM Dial Out), 3038/tcp (Santak UPS), 3379/tcp (SOCORFS), 3292/tcp (Cart O Rama), 3060/tcp (interserver), 3314/tcp (Unify Object Host), 3054/tcp (AMT CNF PROT), 3097/tcp, 3199/tcp (DMOD WorkSpace), 3098/tcp (Universal Message Manager), 3046/tcp (di-ase), 3113/tcp (CS-Authenticate Svr Port), 3122/tcp (MTI VTR Emulator port), 3169/tcp (SERVERVIEW-AS), 3142/tcp (RDC WH EOS), 3162/tcp (SFLM), 3348/tcp (Pangolin Laser), 3000/tcp (RemoteWare Client), 3065/tcp (slinterbase), 3018/tcp (Service Registry), 3302/tcp (MCS Fastmail), 3033/tcp (PDB), 3174/tcp (ARMI Server), 3155/tcp (JpegMpeg Port), 3332/tcp (MCS Mail Server), 3021/tcp (AGRI Server), 3121/tcp, 3188/tcp (Broadcom Port), 3297/tcp (Cytel License Manager), 3376/tcp (CD Broker), 3373/tcp (Lavenir License Manager), 3372/tcp (TIP 2), 3160/tcp (TIP Application Server), 3137/tcp (rtnt-1 data packets), 3198/tcp (Embrace Device Protocol Client), 3052/tcp (APC 3052), 3080/tcp (stm_pproc), 3212/tcp (Survey Instrument), 3111/tcp (Web Synchronous Services), 3037/tcp (HP SAN Mgmt), 3146/tcp (bears-02), 3043/tcp (Broadcast Routing Protocol), 3386/tcp (GPRS Data), 3154/tcp (ON RMI Registry), 3385/tcp (qnxnetman), 3222/tcp (Gateway Load Balancing Pr), 3223/tcp (DIGIVOTE (R) Vote-Server), 3112/tcp (KDE System Guard), 3192/tcp (FireMon Revision Control), 3200/tcp (Press-sense Tick Port), 3170/tcp (SERVERVIEW-ASN), 3229/tcp (Global CD Port), 3384/tcp (Cluster Management Services), 3173/tcp (SERVERVIEW-ICC), 3310/tcp (Dyna Access), 3329/tcp (HP Device Disc), 3241/tcp (SysOrb Monitoring Server), 3328/tcp (Eaglepoint License Manager), 3028/tcp (LiebDevMgmt_DM), 3168/tcp (Now Up-to-Date Public Server), 3281/tcp (SYSOPT), 3125/tcp (A13-AN Interface), 3294/tcp (fg-gip), 3290/tcp (CAPS LOGISTICS TOOLKIT - LM), 3040/tcp (Tomato Springs), 3337/tcp (Direct TV Data Catalog), 3393/tcp (D2K Tapestry Client to Server), 3035/tcp (FJSV gssagt), 3055/tcp (Policy Server), 3392/tcp (EFI License Management), 3083/tcp (TL1-TELNET), 3131/tcp (Net Book Mark), 3025/tcp (Arepa Raft), 3309/tcp (TNS ADV), 3230/tcp (Software Distributor Port), 3056/tcp (CDL Server), 3148/tcp (NetMike Game Administrator), 3153/tcp (S8Cargo Client Port), 3001/tcp, 3228/tcp (DiamondWave MSG Server), 3242/tcp (Session Description ID), 3196/tcp (Network Control Unit), 3053/tcp (dsom-server), 3152/tcp (FeiTian Port), 3206/tcp (IronMail POP Proxy), 3327/tcp (BBARS), 3275/tcp (SAMD), 3024/tcp (NDS_SSO), 3351/tcp (Btrieve port), 3276/tcp (Maxim ASICs), 3074/tcp (Xbox game port), 3394/tcp (D2K Tapestry Server to Server), 3086/tcp (JDL-DBKitchen), 3022/tcp (CSREGAGENT), 3255/tcp (Semaphore Connection Port), 3220/tcp (XML NM over SSL), 3316/tcp (AICC/CMI), 3062/tcp (ncacn-ip-tcp), 3070/tcp (MGXSWITCH), 3284/tcp (4Talk), 3032/tcp (Redwood Chat), 3335/tcp (Direct TV Software Updates), 3183/tcp (COPS/TLS), 3130/tcp (ICPv2), 3099/tcp (CHIPSY Machine Daemon), 3030/tcp (Arepa Cas), 3009/tcp (PXC-NTFY), 3067/tcp (FJHPJP), 3371/tcp, 3128/tcp (Active API Server Port), 3016/tcp (Notify Server), 3147/tcp (RFIO), 3346/tcp (Trnsprnt Proxy), 3010/tcp (Telerate Workstation), 3260/tcp (iSCSI port), 3353/tcp (FATPIPE), 3391/tcp (SAVANT), 3300/tcp, 3194/tcp (Rockstorm MAG protocol), 3238/tcp (appareNet Analysis Server), 3064/tcp (Remote Port Redirector), 3036/tcp (Hagel DUMP), 3011/tcp (Trusted Web), 3082/tcp (TL1-RAW), 3261/tcp (winShadow), 3180/tcp (Millicent Broker Server), 3042/tcp (journee), 3308/tcp (TNS Server), 3279/tcp (admind), 3093/tcp (Jiiva RapidMQ Center), 3066/tcp (NETATTACHSDMP), 3291/tcp (S A Holditch & Associates - LM), 3114/tcp (CCM AutoDiscover), 3193/tcp (SpanDataPort), 3057/tcp (GoAhead FldUp), 3047/tcp (Fast Security HL Server), 3115/tcp (MCTET Master), 3232/tcp (MDT port), 3340/tcp (OMF data m), 3026/tcp (AGRI Gateway), 3331/tcp (MCS Messaging), 3034/tcp (Osmosis / Helix (R) AEEA Port), 3221/tcp (XML NM over TCP), 3355/tcp (Ordinox Dbase), 3190/tcp (ConServR Proxy), 3269/tcp (Microsoft Global Catalog with LDAP/SSL), 3326/tcp (SFTU), 3181/tcp (BMC Patrol Agent), 3338/tcp (OMF data b), 3041/tcp (di-traceware), 3085/tcp (PCIHReq), 3350/tcp (FINDVIATV), 3164/tcp (IMPRS), 3354/tcp (SUITJD), 3110/tcp (simulator control port), 3039/tcp (Cogitate, Inc.), 3101/tcp (HP PolicyXpert PIB Server), 3003/tcp (CGMS), 3374/tcp (Cluster Disc), 3273/tcp (Simple Extensible Multiplexed Protocol), 3157/tcp (CCC Listener Port), 3020/tcp (CIFS), 3145/tcp (CSI-LFAP), 3076/tcp (Orbix 2000 Config), 3078/tcp (Orbix 2000 Locator SSL), 3179/tcp (H2GF W.2m Handover prot.), 3298/tcp (DeskView), 3325/tcp, 3095/tcp (Panasas rendevous port), 3006/tcp (Instant Internet Admin), 3084/tcp (ITM-MCCS), 3177/tcp (Phonex Protocol), 3381/tcp (Geneous), 3165/tcp (Newgenpay Engine Service), 3102/tcp (SoftlinK Slave Mon Port), 3049/tcp (NSWS), 3203/tcp (Network Watcher Monitor), 3068/tcp (ls3 Broadcast), 3089/tcp (ParaTek Agent Linking), 3166/tcp (Quest Spotlight Out-Of-Process Collector), 3090/tcp (Senforce Session Services), 3357/tcp (Adtech Test IP), 3073/tcp (Very simple chatroom prot), 3172/tcp (SERVERVIEW-RM), 3244/tcp (OneSAF), 3233/tcp (WhiskerControl main port), 3094/tcp (Jiiva RapidMQ Registry), 3087/tcp (Asoki SMA), 3333/tcp (DEC Notes), 3048/tcp (Sierra Net PC Trader), 3178/tcp (Radiance UltraEdge Port), 3307/tcp (OP Session Proxy), 3370/tcp, 3258/tcp (Ivecon Server Port), 3133/tcp (Prism Deploy User Port), 3116/tcp (MCTET Gateway), 3341/tcp (OMF data h), 3286/tcp (E-Net), 3186/tcp (IIW Monitor User Port), 3058/tcp (videobeans), 3071/tcp (ContinuStor Manager Port), 3027/tcp (LiebDevMgmt_C), 3312/tcp (Application Management Server), 3072/tcp (ContinuStor Monitor Port), 3138/tcp (rtnt-2 data packets), 3182/tcp (BMC Patrol Rendezvous), 3014/tcp (Broker Service), 3119/tcp (D2000 Kernel Port), 3015/tcp (NATI DSTP), 3365/tcp (Content Server), 3132/tcp (Microsoft Business Rule Engine Update Service), 3342/tcp (WebTIE), 3185/tcp (SuSE Meta PPPD), 3301/tcp, 3361/tcp (KV Agent), 3380/tcp (SNS Channels), 3007/tcp (Lotus Mail Tracking Agent Protocol), 3189/tcp (Pinnacle Sys InfEx Port), 3285/tcp (Plato), 3059/tcp (qsoft), 3117/tcp (MCTET Jserv), 3004/tcp (Csoft Agent), 3176/tcp (ARS Master), 3171/tcp (SERVERVIEW-GF), 3139/tcp (Incognito Rendez-Vous), 3250/tcp (HMS hicp port), 3135/tcp (PeerBook Port), 3002/tcp (RemoteWare Server), 3240/tcp (Trio Motion Control Port), 3382/tcp (Fujitsu Network Enhanced Antitheft function), 3150/tcp (NetMike Assessor Administrator), 3259/tcp (Epson Network Common Devi), 3296/tcp (Rib License Manager), 3108/tcp (Geolocate protocol), 3319/tcp (SDT License Manager), 3149/tcp (NetMike Game Server), 3388/tcp (CB Server), 3239/tcp (appareNet User Interface), 3088/tcp (eXtensible Data Transfer Protocol), 3227/tcp (DiamondWave NMS Server), 3106/tcp (Cardbox HTTP), 3283/tcp (Net Assistant), 3207/tcp (Veritas Authentication Port), 3249/tcp (State Sync Protocol), 3051/tcp (Galaxy Server), 3191/tcp (ConServR SSL Proxy).
BHD Honeypot
Port scan

Port scan from IP: detected by psad.


Black hat directory contains this IP address, because Internet users reported it as an address making unsolicited, nagging requests. We make every effort to ensure that the information contained in the Black hat directory are correct and up to date. The database is developed and updated by Internet users and moderators.

If you have any reliable information regarding malicious activity originating from this IP address, please share it with others and fill in the 'Report breach' form. It is prohibited from adding personally identifiable information.

Below breach categories are used in the database:

  • Denial of service attack - this attack is accomplished by flooding the target with massive amount of requests in order to overload the targeted system
  • Brute force attack - this category encompasses attempts to login to machine by trying many passwords and usernames
  • Backdoor attack - this category represents bypassing authentication by hidden programs or services to obtain remote access to a computer or trojan activity
  • Port scan - represents attackers identifying running services on the targeted machine by probing a server for open ports
  • Malicious bot - this category encompasses all bots performing unsolicited requests or ignoring robots.txt file
  • Anonymous proxy - public proxies like Tor, I2P relays or anonymous VPNs are often used by attacker to hide his identity
  • Web attack - attempts to exploit web application security flaws
  • CMS attack - attempts to exploit CMS vulnerability
  • App vulnerability attack - attempts to exploit other applications vulnerability
  • Web spam - encompasses all kind of HTTP spamming
  • Email spam - encompasses all kind of E-mail spamming
  • Dodgy activity - this category encompasses superfluous, dodgy requests

