IP address


--89.117.104.48
Shodan(more info)
Passive DNS
Tags:
IP blacklists
AbuseIPDB
89.117.104.48 is listed on the AbuseIPDB blacklist.

Description: AbuseIPDB is a project managed by Marathon Studios Inc.<br>Lists IPs performing a malicious activity (DDoS, spam, phishing...)
Type of feed: primary (feed detail page)

Last checked at: 2026-03-31 04:00:00.620000
Was present on blacklist at: 2026-02-25 05:00, 2026-02-27 05:00, 2026-03-13 05:00, 2026-03-31 04:00
BotScout
89.117.104.48 was recently listed on the BotScout blacklist, but currently it is not.

Description: List of bots IPs by BotScout.com (IPs that appeared in last 7 days, as processed by FireHOL).
Type of feed: secondary (feed detail page)

Last checked at: 2026-04-06 04:10:00
Was present on blacklist at: 2026-02-28 04:10, 2026-03-01 04:10, 2026-03-02 04:10, 2026-03-03 04:10, 2026-03-04 04:10, 2026-03-05 04:10, 2026-03-06 04:10
blocklist.de web-login
89.117.104.48 is listed on the blocklist.de web-login blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs that attacks Joomla, Wordpress and<br>other Web-Logins with Brute-Force Logins.
Type of feed: primary (feed detail page)

Last checked at: 2026-04-06 10:05:05.187000
Was present on blacklist at: 2026-04-05 10:05, 2026-04-05 16:05, 2026-04-05 22:05, 2026-04-06 04:05, 2026-04-06 10:05
blocklist.de Apache
89.117.104.48 is listed on the blocklist.de Apache blacklist.

Description: Blocklist.de feed is a free and voluntary service provided<br>by a Fraud/Abuse-specialist. IPs performing attacks on the service<br>Apache, Apache-DDOS, RFI-Attacks.
Type of feed: primary (feed detail page)

Last checked at: 2026-04-06 10:05:05.245000
Was present on blacklist at: 2026-04-05 10:05, 2026-04-05 16:05, 2026-04-05 22:05, 2026-04-06 04:05, 2026-04-06 10:05

Threat categories

TLRoleCategoryDetails
41 src login
37 src

OTX pulses
[69a43d4ad37259001efa142b] 2026-03-01 13:21:14.931000 | VNC honeypot logs for 2026/03/01
Author name:jnazario
Pulse modified:2026-03-01 13:21:14.931000
Indicator created:2026-03-01 13:21:15
Indicator role:None
Indicator title:
Indicator expiration:2026-03-31 13:00:00
[69a58ea2b72d0927b17f56e1] 2026-03-02 13:20:34.077000 | VNC honeypot logs for 2026/03/02
Author name:jnazario
Pulse modified:2026-03-02 13:20:34.077000
Indicator created:2026-03-02 13:20:35
Indicator role:None
Indicator title:
Indicator expiration:2026-04-01 13:00:00
[69a8340fa1932fb5dbb859ee] 2026-03-04 13:30:55.779000 | VNC honeypot logs for 2026/03/04
Author name:jnazario
Pulse modified:2026-03-04 13:30:55.779000
Indicator created:2026-03-04 13:30:56
Indicator role:None
Indicator title:
Indicator expiration:2026-04-03 13:00:00
[69a98476d300a235ceb63910] 2026-03-05 13:26:14.166000 | VNC honeypot logs for 2026/03/05
Author name:jnazario
Pulse modified:2026-03-05 13:26:14.166000
Indicator created:2026-03-05 13:26:16
Indicator role:None
Indicator title:
Indicator expiration:2026-04-04 13:00:00
Origin AS
AS209854 - SURFSHARK
BGP Prefix
89.117.104.0/24
geo
Germany, Frankfurt am Main
🕑 Europe/Berlin
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
89.117.104.0 - 89.117.107.255
last_activity
2026-03-05 16:39:26.380000
reserved_range
0
Shodan's InternetDB
Open ports: 4000, 7443
Tags:
CPEs:
ts_added
2026-02-25 05:00:56.839000
ts_last_update
2026-04-06 10:08:14.695000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses