IP address


--85.113.70.154
Shodan(more info)
Passive DNS
Tags:
IP blacklists
DataPlane VNC RFB
85.113.70.154 is listed on the DataPlane VNC RFB blacklist.

Description: DataPlane.org is a community-powered Internet data, feeds,<br>and measurement resource for operators, by operators. IPs initiating<br>an unsolicited VNC remote frame buffer (RFB) session to a remote host.
Type of feed: primary (feed detail page)

Last checked at: 2026-02-21 23:10:00.515000
Was present on blacklist at: 2026-02-14 23:10, 2026-02-15 03:10, 2026-02-15 07:10, 2026-02-15 11:10, 2026-02-15 15:10, 2026-02-15 19:10, 2026-02-15 23:10, 2026-02-16 03:10, 2026-02-16 07:10, 2026-02-16 11:10, 2026-02-16 15:10, 2026-02-16 19:10, 2026-02-16 23:10, 2026-02-17 03:10, 2026-02-17 07:10, 2026-02-17 11:10, 2026-02-17 15:10, 2026-02-17 19:10, 2026-02-17 23:10, 2026-02-18 03:10, 2026-02-18 07:10, 2026-02-18 11:10, 2026-02-18 15:10, 2026-02-18 19:10, 2026-02-18 23:10, 2026-02-19 03:10, 2026-02-19 07:10, 2026-02-19 11:10, 2026-02-19 15:10, 2026-02-19 19:10, 2026-02-19 23:10, 2026-02-20 03:10, 2026-02-20 07:10, 2026-02-20 11:10, 2026-02-20 15:10, 2026-02-20 19:10, 2026-02-20 23:10, 2026-02-21 03:10, 2026-02-21 07:10, 2026-02-21 11:10, 2026-02-21 15:10, 2026-02-21 19:10, 2026-02-21 23:10

Threat categories

TLRoleCategoryDetails
25 src login protocol: vnc

OTX pulses
[69931a666448b1cf5c48e0d1] 2026-02-16 13:23:50.426000 | VNC honeypot logs for 2026/02/16
Author name:jnazario
Pulse modified:2026-02-16 13:23:50.426000
Indicator created:2026-02-16 13:23:51
Indicator role:None
Indicator title:
Indicator expiration:2026-03-18 13:00:00
[69946d83d7c9dffdcb3d5354] 2026-02-17 13:30:43.105000 | VNC honeypot logs for 2026/02/17
Author name:jnazario
Pulse modified:2026-02-17 13:30:43.105000
Indicator created:2026-02-17 13:30:44
Indicator role:None
Indicator title:
Indicator expiration:2026-03-19 13:00:00
[6995bcbf6d049ab7b7ab3d98] 2026-02-18 13:21:03.465000 | VNC honeypot logs for 2026/02/18
Author name:jnazario
Pulse modified:2026-02-18 13:21:03.465000
Indicator created:2026-02-18 13:21:04
Indicator role:None
Indicator title:
Indicator expiration:2026-03-20 13:00:00
[69970e3563fbadf109a49c80] 2026-02-19 13:20:53.679000 | VNC honeypot logs for 2026/02/19
Author name:jnazario
Pulse modified:2026-02-19 13:20:53.679000
Indicator created:2026-02-19 13:20:54
Indicator role:None
Indicator title:
Indicator expiration:2026-03-21 13:00:00
[69985fb2bba6f786cb7798e6] 2026-02-20 13:20:50.164000 | VNC honeypot logs for 2026/02/20
Author name:jnazario
Pulse modified:2026-02-20 13:20:50.164000
Indicator created:2026-02-20 13:20:51
Indicator role:None
Indicator title:
Indicator expiration:2026-03-22 13:00:00
[6999b154618c9980bc591d6b] 2026-02-21 13:21:24.470000 | VNC honeypot logs for 2026/02/21
Author name:jnazario
Pulse modified:2026-02-21 13:21:24.470000
Indicator created:2026-02-21 13:21:25
Indicator role:None
Indicator title:
Indicator expiration:2026-03-23 13:00:00
Origin AS
AS3258 - XTOM-TOKYO
BGP Prefix
85.113.70.0/24
geo
Japan
🕑 Asia/Tokyo
hostname
(null)
Address block ('inetnum' or 'NetRange' in whois database)
85.113.70.0 - 85.113.71.255
last_activity
2026-02-21 16:41:26.459000
reserved_range
0
Shodan's InternetDB
Open ports: 21, 22, 80, 443, 8888
Tags: self-signed, starttls
CPEs: cpe:/a:f5:nginx, cpe:/a:openbsd:openssh:8.0, cpe:/a:pureftpd:pure-ftpd
ts_added
2026-02-14 23:10:02.270000
ts_last_update
2026-02-21 23:10:12.823000

Warden event timeline

DShield event timeline

Presence on blacklists

OTX pulses