Report for IP: 15.235.5.241

Threat LevelMEDIUM46/1001 rule type
2 incidents on record · persistent 30-day campaign · last seen 6d ago
PTR ip241.ip-15-235-5.net
Org / ASN NUBE, IINTEGRA
Country 🇲🇽 Mexico
City Guadalajara, Jalisco
Timezone America/Mexico_City

Attack Analysis

🇨🇦 Canada · Ottawa · 16276 · OVH Hosting, Inc.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.

Reports (2)

Date Severity Description
25 Jul 2026 - 16:51 high IDS: Database port scan — ET SCAN Suspicious inbound to MSSQL port 1433
25 Jun 2026 - 19:31 high IDS: Database port scan — ET SCAN Suspicious inbound to MSSQL port 1433