// public entity intelligence
20.168.11.172
Evidence summary
Researcher feed observations and neutral DNS history are counted separately.
Tags
Sources
Observed 17 times. Targeted ports: 5984. Country: United States. Reputation: known attacker. Alert categories: Detection of a Network Scan. Signatures: ET SCAN Zmap User-Agent (Inbound).
| Indicator | Type | Tag | Source | Last seen |
|---|---|---|---|---|
| 20.168.11.172 | ip | honeypot, historical | 2026-09-21 01:32:22 | |
Honeypot infrastructure watch: Observed 17 times. Targeted ports: 5984. Country: United States. Reputation: known attacker. Alert categories: Detection of a Network Scan. Signatures: ET SCAN Zmap User-Agent (Inbound). | ||||
Related hosts and IPs
Public passive DNS relationships connected to this exact indicator.
Network ownership
BGP origin and registry data from Team Cymru.
MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US
Registry country is RIR assignment data, not IP geolocation.
Checked 9/21/2026, 1:32:50 AM
Popularity
Daily link and hosting prominence from top1m.org; not a security verdict or traffic estimate.
Not present in the current Top 1M lists.
Take this investigation further
1 public pDNS relationships are available. Private research adds exact timing, focused pivots, and matching paid-feed intelligence. Each private app search costs 1 CTIDAO.