IP address


.003109.104.134.239
Shodan(more info)
Passive DNS
Tags:
IP blacklists
Echelon VNC login
109.104.134.239 is listed on the Echelon VNC login blacklist.

Description: IPs detected by Echelon sensors (honeypots) as performing this activity: VNC remote desktop login attempt on port 5900/5901
Type of feed: primary (feed detail page)

Last checked at: 2026-09-07 09:45:00.327000
Was present on blacklist at: 2026-08-31 09:45, 2026-09-01 09:45, 2026-09-02 09:45, 2026-09-03 09:45, 2026-09-04 09:45, 2026-09-05 09:45, 2026-09-06 09:45, 2026-09-07 09:45

Threat categories

TLRoleCategoryDetails
25 src login protocol: vnc

OTX pulses
[6a9571ce4cd78dce232262fa] 2026-08-31 12:21:34.147000 | VNC honeypot logs for 2026/08/31
Author name:jnazario
Pulse modified:2026-08-31 12:21:34.147000
Indicator created:2026-08-31 12:21:35
Indicator role:None
Indicator title:
Indicator expiration:2026-09-30 12:00:00
Origin AS
AS203020 - HostRoyale
BGP Prefix
109.104.134.0/24
geo
Netherlands
🕑 Europe/Amsterdam
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
109.104.134.0 - 109.104.135.255
last_activity
2026-09-03 09:54:43.491000
rep
0.003340630624616203
reserved_range
0
ts_added
2026-08-31 09:45:02.118000
ts_last_update
2026-09-19 09:45:15.278000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses