Threat LevelHIGH59/1002 rule types across 2 attack categories
7 incidents on record · 2 rule types · confirmed on global blocklist · persistent 49-day campaign · last seen 6d ago
| PTR | mail.moss-chat.com.cn |
| Org / ASN | Ucloud Information Technology (hk) Limited |
| Country | 🇭🇰 Hong Kong |
| City | Hong Kong, Kowloon |
| Timezone | Asia/Hong_Kong |
Attack Analysis
IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
Reports (7)
| Date | Severity | Description |
|---|---|---|
| 26 Jul 2026 - 05:16 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
| 24 Jul 2026 - 05:11 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
| 17 Jul 2026 - 04:12 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
| 17 Jul 2026 - 04:12 | high | IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306 |
| 12 Jun 2026 - 08:45 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
| 7 Jun 2026 - 18:16 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
| 7 Jun 2026 - 09:19 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 17 |
EagleEye Intelligence