Introduction
n8n is a workflow automation platform used to connect applications, APIs, databases, webhooks and AI services. It has legitimate uses including IT automation, data processing, API integration and AI workflows.
The supplied intelligence identified 374 internet-facing hosts associated with n8n across 75 ASNs, with infrastructure concentrated in Germany, the Netherlands, the United States, Russia and Sweden. Several hosts were additionally associated with bulletproof hosting, brute-force activity, Gophish, Open WebUI, Ollama and AdaptixC2.
The presence of n8n alone does not indicate malicious activity. The purpose of this analysis was to validate the reported associations using independent infrastructure observations and identify relationships between the highlighted hosts.
Key Findingsn8n Infrastructure
Independent Shodan observations confirmed n8n on:
-
46.226.160.172 -
147.45.70.94 -
35.238.107.17 -
165.22.254.150
n8n was also independently observed on 193.134.209.39 within the separately analyzed 193.134.209.0/24 network.
Bulletproof Hosting Association
Five hosts were originally reported as n8n + Bulletproof Hosting (BPH).
The BPH association could not be independently confirmed using the available enrichment data.
Therefore, the BPH classification should be treated as an original intelligence-source claim rather than independently confirmed evidence.
Brute-Force Activity
Two IPs were reported as being associated with brute-force activity:
-
165.22.254.150 -
185.128.138.138
The enrichment data showed significant abuse-reporting history for both addresses.
165.22.254.150 had 1,644 reports with 100% abuse confidence, while 185.128.138.138 had 511 reports with 100% abuse confidence. However, these reports do not establish that the activity was specifically related to n8n or Open WebUI.
Gophish Association
35.238.107.17 was originally reported as n8n + Gophish.
n8n was independently confirmed on the host, but the Gophish association could not be independently verified using the available evidence.
AI and C2 Association
202.191.67.71 was reported as hosting:
- n8n
- Ollama
- AdaptixC2
These three service associations could not be independently confirmed using the available evidence.
The combination makes the host a high-interest indicator for further validation, but does not prove that the services were integrated or used maliciously.
Analysis of the193.134.209.0/24 Network
The original intelligence reported nine observed hosts within 193.134.209.0/24.
Because the original nine IP addresses were not provided, the network was independently queried using Shodan. This produced ten currently observable hosts within the same /24.
All ten observed hosts were associated with:
- ASN: AS139659
- Provider: Cloudco LLC / LUCIDACLOUD LIMITED
- Country: Hong Kong
The hosts exposed different services including Nginx, OpenSSH, Pure-FTPd, MySQL, Gunicorn/Python, Portmapper, API services and n8n.
One host, 193.134.209.39, was independently identified as an n8n host with the hostname:
n8n.wtn.wang
It also exposed Nginx and Pure-FTPd.
Important observation
The original intelligence reported 9 hosts, while Shodan currently showed 10 hosts.
This difference should be treated as a data discrepancy, not as evidence that either source is incorrect. Possible reasons include different observation times, scan coverage and infrastructure changes.
Infrastructure CorrelationThe ten observed hosts within the /24 share the same:
ASN → AS139659
Provider → Cloudco LLC / LUCIDACLOUD LIMITED
Country → Hong Kong
This establishes a common network and hosting relationship.
However, shared ASN or provider information does not prove common ownership, common administration, malicious intent or control by a single threat actor.
The different services observed across the hosts also show that the /24 is not simply a group of identical n8n servers.
Security teams investigating similar infrastructure should consider monitoring for:
- Internet-facing n8n instances exposed without appropriate access controls
- Unexpected n8n deployments on infrastructure
- Hosts associated with multiple suspicious services
- Repeated authentication attempts against exposed services
- Unexpected web-facing automation platforms
- Infrastructure sharing the same ASN or provider
- Changes in services exposed by hosts within the same network
-
New hosts appearing within a previously observed
/24
Infrastructure relationships should be correlated with endpoint, network and authentication telemetry before determining malicious activity.
AssessmentThe analysis confirms the presence of n8n on several highlighted hosts and independently identifies n8n within the 193.134.209.0/24 network.
The brute-force-associated IPs have supporting abuse-reporting evidence, while the BPH, Gophish and AI/C2 associations remain unconfirmed.
The findings therefore represent threat-intelligence leads and infrastructure relationships rather than proof that every identified host is malicious.
ConclusionThe analysis shows how an apparently legitimate automation platform can appear within infrastructure that also has suspicious threat-intelligence associations.
Several reported n8n associations were independently validated, while other associations require further investigation. The 193.134.209.0/24 analysis also demonstrated a common ASN, provider and geographic relationship across ten currently observable hosts, including one independently confirmed n8n host.
These findings can support continued monitoring and enrichment of the identified infrastructure, but they do not independently establish malicious activity or common threat-actor control.