180.97.183.152
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of 180.97.183.152
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
Autonomous System
Geolocation
Reverse DNS
Network
Open Ports
| Port | Proto | Service | Server | Last seen |
|---|---|---|---|---|
| 21 | tcp | ftp | — | 2026-05-26 08:26:48.000 |
| 23 | tcp | telnet | — | 2026-05-27 05:29:59.000 |
| 25 | tcp | smtp | — | 2026-07-18 06:05:32.000 |
| 79 | tcp | — | — | 2026-06-15 17:33:02.000 |
| 80 | tcp | http | — | 2026-06-23 06:25:38.000 |
| 162 | tcp | — | — | 2026-07-21 05:13:15.000 |
| 175 | tcp | — | — | 2026-07-26 20:22:45.000 |
| 427 | tcp | — | — | 2026-06-22 02:31:14.000 |
| 443 | tcp | https | nginx/1.21.6 | 2026-07-20 19:00:55.000 |
| 444 | tcp | — | — | 2026-07-23 01:58:47.000 |
| 502 | tcp | — | — | 2026-07-22 12:17:49.000 |
| 520 | tcp | — | — | 2026-07-19 20:47:54.000 |
| 953 | tcp | — | — | 2026-06-21 16:34:04.000 |
| 981 | tcp | — | — | 2026-06-15 19:19:14.000 |
| 992 | tcp | — | — | 2026-07-20 02:52:44.000 |
| 993 | tcp | imaps | — | 2026-05-26 23:15:21.000 |
| 1241 | tcp | — | — | 2026-07-22 09:57:39.000 |
| 1604 | tcp | — | — | 2026-06-15 16:01:56.000 |
| 2087 | tcp | — | — | 2026-06-17 13:43:20.000 |
| 2222 | tcp | ssh-alt | — | 2026-07-21 01:32:26.000 |
| 2375 | tcp | docker | — | 2026-07-16 01:30:06.000 |
| 2717 | tcp | — | — | 2026-07-21 10:24:24.000 |
| 2967 | tcp | — | — | 2026-06-07 15:32:09.000 |
| 3128 | tcp | — | — | 2026-06-15 21:36:38.000 |
| 3457 | tcp | — | — | 2026-07-22 01:17:32.000 |
| 3724 | tcp | — | — | 2026-06-22 15:10:36.000 |
| 4045 | tcp | — | — | 2026-06-14 16:06:21.000 |
| 4222 | tcp | nats | — | 2026-07-27 00:47:35.000 |
| 4567 | tcp | — | — | 2026-06-20 05:32:33.000 |
| 5000 | tcp | — | — | 2026-06-09 20:39:34.000 |
| 5044 | tcp | logstash-beats | — | 2026-06-22 12:24:29.000 |
| 5060 | tcp | sip | — | 2026-06-18 09:13:23.000 |
| 5222 | tcp | — | — | 2026-06-15 18:47:47.000 |
| 5357 | tcp | — | — | 2026-06-17 06:04:41.000 |
| 5800 | tcp | — | — | 2026-07-26 10:30:48.000 |
| 5902 | tcp | — | — | 2026-06-15 08:14:00.000 |
| 6379 | tcp | redis | — | 2026-07-27 01:38:43.000 |
| 6443 | tcp | kubernetes | — | 2026-06-15 15:37:06.000 |
| 6665 | tcp | — | — | 2026-07-18 20:18:52.000 |
| 6667 | tcp | — | — | 2026-05-31 06:36:44.000 |
| 7070 | tcp | — | — | 2026-06-15 02:23:29.000 |
| 7474 | tcp | — | — | 2026-06-17 19:45:09.000 |
| 8222 | tcp | — | — | 2026-07-24 23:56:34.000 |
| 8333 | tcp | — | — | 2026-06-15 06:28:46.000 |
| 8444 | tcp | — | — | 2026-06-22 06:37:20.000 |
| 9009 | tcp | — | — | 2026-07-19 07:18:39.000 |
| 9043 | tcp | — | — | 2026-06-18 05:10:07.000 |
| 9090 | tcp | — | — | 2026-06-17 17:58:31.000 |
| 9091 | tcp | — | — | 2026-07-20 20:35:38.000 |
| 10255 | tcp | — | — | 2026-06-13 14:25:39.000 |
| 11211 | tcp | memcached | — | 2026-07-23 08:13:55.000 |
| 33060 | tcp | — | — | 2026-06-19 02:54:38.000 |
| 49152 | tcp | — | — | 2026-07-17 04:56:05.000 |
TLS Certificates
Tech Stack
Wappalyzer fingerprinting pending
HTTP-body analysis identifies web frameworks, CMS platforms, analytics, JS libraries and server-side languages from this host.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-leak candidates for this IP
When this IP serves a TLS cert for a domain that fronts behind a CDN, that domain surfaces here as an origin-leak candidate with a confidence score.
Multi-Vantage Check
Reachability accrued passively from real user-triggered checks across our 65+ probe nodes. Run a live check to add fresh data.
No accumulated reachability data yet
Reachability accrues from real user-triggered checks. Trigger a Ping or HTTP check from our 65+ probe nodes to contribute the first data point.
Web Pages
| Port | Page title | Status | Flags |
|---|---|---|---|
| 443 | Welcome to nginx! | 200 |
Threat Intelligence
No threat-intel matches
This IP doesn't appear in any of the feeds we mirror (Tor exits, FireHOL Level 1-3, Spamhaus DROP/EDROP, URLhaus, OpenPhish). Absence here doesn't prove the IP is clean — it just means none of our public-feed sources flag it.
Co-Hosted Domains
No DNS-confirmed domains yet
We cross-reference body-cited domains against our DNS resolver records. Confirmations appear here once both sides have data for the same name.
History
The full change-log (ASN moves, cert rotations, port-state diffs) accumulates as our archives grow.