165.232.117.238
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of 165.232.117.238
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
Autonomous System
Geolocation
Reverse DNS
Network
Open Ports
| Port | Proto | Service | Server | Last seen |
|---|---|---|---|---|
| 443 | tcp | https | Apache/2.4.52 | 2026-07-23 00:56:19.000 |
TLS Certificates
Tech Stack
Detected via Wappalyzer-style rules on the HTTP response body, headers, scripts and meta tags.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-leak candidates for this IP
When this IP serves a TLS cert for a domain that fronts behind a CDN, that domain surfaces here as an origin-leak candidate with a confidence score.
Hosted Domains
2 domains resolve (A-record) to this IP.
Multi-Vantage Check
Reachability accrued passively from real user-triggered checks across our 65+ probe nodes. Run a live check to add fresh data.
No accumulated reachability data yet
Reachability accrues from real user-triggered checks. Trigger a Ping or HTTP check from our 65+ probe nodes to contribute the first data point.
Web Pages
| Port | Page title | Status | Flags |
|---|---|---|---|
| 443 | CitadelaWP theme for Business, eCommerce & Content sites | Ait Themes | 200 |
Threat Intelligence
No threat-intel matches
This IP doesn't appear in any of the feeds we mirror (Tor exits, FireHOL Level 1-3, Spamhaus DROP/EDROP, URLhaus, OpenPhish). Absence here doesn't prove the IP is clean — it just means none of our public-feed sources flag it.
Honeypot Activity
This IP hit our honeypot sensors 12 times in the last 90 days — unsolicited connections to services we never advertise, a strong scanner / brute-force signal.
| Time | Port | Proto | Event | Credentials / payload |
|---|---|---|---|---|
| 2026-08-01 16:37:20 | 5060 | sip | udp_probe | ..{."'y@V.).~.G..MMorO.<f..w.qw.rr2..+.. |
| 2026-07-30 07:13:43 | 5060 | sip | udp_probe | ?.Pv<U!.(<a.K.A/.J.=.? |
| 2026-07-24 17:53:21 | 1900 | ssdp | udp_probe | ..yH$.P.[.r.J)UJER,...lxJ%j.[+. ..R7 "Pd(Ccsl9=1.i2$l..6C.H.2O(EPz}Y.M>D.!7}Z.. |
| 2026-07-20 10:23:40 | 1900 | ssdp | udp_probe | Y.(kl6 1.o<..#6I&s.'.I.Y/ WC"_....{=.,>.hW.. N2.]Y.'l^Vv~.9! V0._+QqW.r@fwLsE~t#WxJCV 9UNrv[I&.. |
| 2026-07-19 18:28:54 | 1900 | ssdp | udp_probe | i.=.9.k^fq.-yq..C8..f6FmPD L.OMn] s.&^u.O.9H.A\DypO`&.MvZWC_&.M..@.A..Nn .6.. |
| 2026-07-15 19:01:11 | 5060 | sip | udp_probe | W. .. |
| 2026-07-06 14:13:17 | 1900 | ssdp | udp_probe | ].Z9<.. |
| 2026-07-04 09:12:18 | 5060 | sip | udp_probe | ..b.. V ..1.2n\Z Y6.`r;y.{@Ai.'.- .B.aO!w.8*n...n:)N,dHH`. I'0HT9T.M5eY. |
| 2026-07-01 18:20:46 | 1900 | ssdp | udp_probe | 9.Vx"C y.H&..pONeL=e.. |
| 2026-06-30 23:53:52 | 1900 | ssdp | udp_probe | V.I4.oaH_;\.CLE .4p9S6Ih..58vYpL.9..(aa..=.` N...qSU'.>2.sj%LZqT.rm;SNCk_ |
| 2026-06-28 18:37:23 | 5060 | sip | udp_probe | j.!.lpm.|N;R.=.OI..'.V....HiB.8,IX- |
| 2026-06-27 10:46:26 | 1900 | ssdp | udp_probe | #.Q@...-.I!.{3.x[3+>`^.YWVl.aOG.p.D..\.9 |
Co-Hosted Domains
Domains this host references in its HTML AND whose DNS A/AAAA record resolves back to this IP — i.e. actually hosted here.
External References
Domains the body links to whose DNS does NOT resolve to this IP — usually CDN assets, embeds, or third-party services. Boilerplate (Google Fonts, jsDelivr, w3.org…) is already filtered.
History
The full change-log (ASN moves, cert rotations, port-state diffs) accumulates as our archives grow.