IP address


--89.117.104.18
Shodan(more info)
Passive DNS
Tags:
IP blacklists
AbuseIPDB
89.117.104.18 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-03-16 05:00:00.655000
Was present on blacklist at: 2026-03-16 05:00
BotScout
89.117.104.18 was recently listed on the BotScout blacklist, but currently it is not.

Description: List of bots IPs by BotScout.com (IPs that appeared in last 7 days, as processed by FireHOL).
Type of feed: secondary (feed detail page)

Last checked at: 2026-04-05 16:10:00
Was present on blacklist at: 2026-03-26 16:10, 2026-03-27 16:10, 2026-03-28 16:10, 2026-03-29 16:10, 2026-03-30 16:10, 2026-03-31 16:10, 2026-04-01 16:10, 2026-04-02 16:10

Threat categories

TLRoleCategoryDetails
No threat category tags assigned

OTX pulses
[69a43d4ad37259001efa142b] 2026-03-01 13:21:14.931000 | VNC honeypot logs for 2026/03/01
Author name:jnazario
Pulse modified:2026-03-01 13:21:14.931000
Indicator created:2026-03-01 13:21:15
Indicator role:None
Indicator title:
Indicator expiration:2026-03-31 13:00:00
[69a58ea2b72d0927b17f56e1] 2026-03-02 13:20:34.077000 | VNC honeypot logs for 2026/03/02
Author name:jnazario
Pulse modified:2026-03-02 13:20:34.077000
Indicator created:2026-03-02 13:20:35
Indicator role:None
Indicator title:
Indicator expiration:2026-04-01 13:00:00
[69a8340fa1932fb5dbb859ee] 2026-03-04 13:30:55.779000 | VNC honeypot logs for 2026/03/04
Author name:jnazario
Pulse modified:2026-03-04 13:30:55.779000
Indicator created:2026-03-04 13:30:56
Indicator role:None
Indicator title:
Indicator expiration:2026-04-03 13:00:00
Origin AS
AS209854 - SURFSHARK
BGP Prefix
89.117.104.0/24
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
89.117.104.0 - 89.117.107.255
last_activity
2026-03-04 16:39:31.690000
reserved_range
0
Shodan's InternetDB
Open ports: 4000, 8443
Tags:
CPEs:
ts_added
2026-03-01 16:40:05.596000
ts_last_update
2026-04-05 16:40:10.835000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses