ThreatBeaconXThreatBeaconXSubscribe
MediumCloud · 6 min read · 49 views

n8n Infrastructure: Analysis of Internet-Facing Hosts and Threat Associations

An analysis of internet-facing n8n infrastructure identified associations with bulletproof hosting, brute-force activity, Gophish and AI/C2 infrastructure. Independent enrichment confirmed n8n on several hosts and analyzed the reported 193.134.209.0/24 network, where nine hosts were originally reported and ten were subsequently observed through Shodan.

Written by Sai Swetha·Published Aug 28, 2026
n8n Infrastructure and Threat Associations

Introduction

n8n is a workflow automation platform used to connect applications, APIs, databases, webhooks and AI services. It has legitimate uses including IT automation, data processing, API integration and AI workflows.

The supplied intelligence identified 374 internet-facing hosts associated with n8n across 75 ASNs, with infrastructure concentrated in Germany, the Netherlands, the United States, Russia and Sweden. Several hosts were additionally associated with bulletproof hosting, brute-force activity, Gophish, Open WebUI, Ollama and AdaptixC2.

The presence of n8n alone does not indicate malicious activity. The purpose of this analysis was to validate the reported associations using independent infrastructure observations and identify relationships between the highlighted hosts.

Key Findings

n8n Infrastructure

Independent Shodan observations confirmed n8n on:

  • 46.226.160.172
  • 147.45.70.94
  • 35.238.107.17
  • 165.22.254.150

n8n was also independently observed on 193.134.209.39 within the separately analyzed 193.134.209.0/24 network.

Bulletproof Hosting Association

Five hosts were originally reported as n8n + Bulletproof Hosting (BPH).

The BPH association could not be independently confirmed using the available enrichment data.

Therefore, the BPH classification should be treated as an original intelligence-source claim rather than independently confirmed evidence.

Brute-Force Activity

Two IPs were reported as being associated with brute-force activity:

  • 165.22.254.150
  • 185.128.138.138

The enrichment data showed significant abuse-reporting history for both addresses.

165.22.254.150 had 1,644 reports with 100% abuse confidence, while 185.128.138.138 had 511 reports with 100% abuse confidence. However, these reports do not establish that the activity was specifically related to n8n or Open WebUI.

Gophish Association

35.238.107.17 was originally reported as n8n + Gophish.

n8n was independently confirmed on the host, but the Gophish association could not be independently verified using the available evidence.

AI and C2 Association

202.191.67.71 was reported as hosting:

  • n8n
  • Ollama
  • AdaptixC2

These three service associations could not be independently confirmed using the available evidence.

The combination makes the host a high-interest indicator for further validation, but does not prove that the services were integrated or used maliciously.

Analysis of the 193.134.209.0/24 Network

The original intelligence reported nine observed hosts within 193.134.209.0/24.

Because the original nine IP addresses were not provided, the network was independently queried using Shodan. This produced ten currently observable hosts within the same /24.

All ten observed hosts were associated with:

  • ASN: AS139659
  • Provider: Cloudco LLC / LUCIDACLOUD LIMITED
  • Country: Hong Kong

The hosts exposed different services including Nginx, OpenSSH, Pure-FTPd, MySQL, Gunicorn/Python, Portmapper, API services and n8n.

One host, 193.134.209.39, was independently identified as an n8n host with the hostname:

n8n.wtn.wang

It also exposed Nginx and Pure-FTPd.

Important observation

The original intelligence reported 9 hosts, while Shodan currently showed 10 hosts.

This difference should be treated as a data discrepancy, not as evidence that either source is incorrect. Possible reasons include different observation times, scan coverage and infrastructure changes.

Infrastructure Correlation

The ten observed hosts within the /24 share the same:

ASN → AS139659

Provider → Cloudco LLC / LUCIDACLOUD LIMITED

Country → Hong Kong

This establishes a common network and hosting relationship.

However, shared ASN or provider information does not prove common ownership, common administration, malicious intent or control by a single threat actor.

The different services observed across the hosts also show that the /24 is not simply a group of identical n8n servers.

Detection and Investigation Considerations

Security teams investigating similar infrastructure should consider monitoring for:

  • Internet-facing n8n instances exposed without appropriate access controls
  • Unexpected n8n deployments on infrastructure
  • Hosts associated with multiple suspicious services
  • Repeated authentication attempts against exposed services
  • Unexpected web-facing automation platforms
  • Infrastructure sharing the same ASN or provider
  • Changes in services exposed by hosts within the same network
  • New hosts appearing within a previously observed /24

Infrastructure relationships should be correlated with endpoint, network and authentication telemetry before determining malicious activity.

Assessment

The analysis confirms the presence of n8n on several highlighted hosts and independently identifies n8n within the 193.134.209.0/24 network.

The brute-force-associated IPs have supporting abuse-reporting evidence, while the BPH, Gophish and AI/C2 associations remain unconfirmed.

The findings therefore represent threat-intelligence leads and infrastructure relationships rather than proof that every identified host is malicious.

Conclusion

The analysis shows how an apparently legitimate automation platform can appear within infrastructure that also has suspicious threat-intelligence associations.

Several reported n8n associations were independently validated, while other associations require further investigation. The 193.134.209.0/24 analysis also demonstrated a common ASN, provider and geographic relationship across ten currently observable hosts, including one independently confirmed n8n host.

These findings can support continued monitoring and enrichment of the identified infrastructure, but they do not independently establish malicious activity or common threat-actor control.

Indicators of Compromise

TypeValueNotes
IPv446.226.160.172
IPv462.60.228.187
IPv484.22.150.239
IPv4147.45.70.94
IPv4193.47.60.29
IPv4165.22.254.150
IPv4185.128.138.138
IPv435.238.107.17
IPv4202.191.67.71
IPv4193.134.209.39

MITRE ATT&CK Mapping

T1046 — Network Service Scanning