IP address


--109.120.137.150135909.h2.nexus
Shodan(more info)
Passive DNS
Tags:
DShield reports (IP summary, reports)
2025-04-04
Number of reports: 282
Distinct targets: 52
OTX pulses
[67f7b8da683933c97849c585] 2025-04-10 12:26:02.090000 | PostgresQL honeypot logs for 2025-04-10
Author name:jnazario
Pulse modified:2025-04-10 12:26:02.090000
Indicator created:2025-04-10 12:26:02
Indicator role:None
Indicator title:
Indicator expiration:2025-05-10 12:00:00
[67f90a5f3dcccdd41f537e91] 2025-04-11 12:26:07.025000 | PostgresQL honeypot logs for 2025-04-11
Author name:jnazario
Pulse modified:2025-04-11 12:26:07.025000
Indicator created:2025-04-11 12:26:07
Indicator role:None
Indicator title:
Indicator expiration:2025-05-11 12:00:00
[67fa5c285d8bf54c5fe2d5c0] 2025-04-12 12:27:18.062000 | PostgresQL honeypot logs for 2025-04-12
Author name:jnazario
Pulse modified:2025-04-12 12:27:18.062000
Indicator created:2025-04-12 12:27:22
Indicator role:None
Indicator title:
Indicator expiration:2025-05-12 12:00:00
Origin AS
AS215730 - H2NEXUS-AS
BGP Prefix
109.120.137.0/24
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
135909.h2.nexus
Address block ('inetnum' or 'NetRange' in whois database)
109.120.128.0 - 109.120.159.255
last_activity
2025-04-12 16:38:29.779000
reserved_range
0
Shodan's InternetDB
Open ports: 135, 445, 3389
Tags: self-signed
CPEs:
ts_added
2025-04-05 05:01:27.400000
ts_last_update
2025-05-15 05:01:52.320000

Warden event timeline

DShield event timeline

OTX pulses