IP address


--89.117.104.31
Shodan(more info)
Passive DNS
Tags:
IP blacklists
BotScout
89.117.104.31 is listed on the BotScout blacklist.

Description: List of bots IPs by BotScout.com (IPs that appeared in last 7 days, as processed by FireHOL).
Type of feed: secondary (feed detail page)

Last checked at: 2026-04-05 16:10:00
Was present on blacklist at: 2026-03-13 16:10, 2026-03-14 16:10, 2026-03-15 16:10, 2026-03-16 16:10, 2026-03-17 16:10, 2026-03-18 16:10, 2026-03-19 16:10, 2026-03-20 16:10, 2026-04-01 16:10, 2026-04-02 16:10, 2026-04-03 16:10, 2026-04-04 16:10, 2026-04-05 16:10

Threat categories

TLRoleCategoryDetails
No threat category tags assigned

OTX pulses
[69a43d4ad37259001efa142b] 2026-03-01 13:21:14.931000 | VNC honeypot logs for 2026/03/01
Author name:jnazario
Pulse modified:2026-03-01 13:21:14.931000
Indicator created:2026-03-01 13:21:15
Indicator role:None
Indicator title:
Indicator expiration:2026-03-31 13:00:00
[69a58ea2b72d0927b17f56e1] 2026-03-02 13:20:34.077000 | VNC honeypot logs for 2026/03/02
Author name:jnazario
Pulse modified:2026-03-02 13:20:34.077000
Indicator created:2026-03-02 13:20:35
Indicator role:None
Indicator title:
Indicator expiration:2026-04-01 13:00:00
[69a8340fa1932fb5dbb859ee] 2026-03-04 13:30:55.779000 | VNC honeypot logs for 2026/03/04
Author name:jnazario
Pulse modified:2026-03-04 13:30:55.779000
Indicator created:2026-03-04 13:30:56
Indicator role:None
Indicator title:
Indicator expiration:2026-04-03 13:00:00
Origin AS
AS209854 - SURFSHARK
BGP Prefix
89.117.104.0/24
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
89.117.104.0 - 89.117.107.255
last_activity
2026-03-04 16:39:31.717000
reserved_range
0
Shodan's InternetDB
Open ports: 1443, 4000, 7443, 8443
Tags:
CPEs:
ts_added
2026-03-01 16:40:05.635000
ts_last_update
2026-04-05 16:40:11.178000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses