Threat LevelHIGH60/1002 rule types across 2 attack categories
2 incidents on record · 2 rule types · active attack detected · persistent 17-day campaign · seen 15h ago · known internet scanner
| PTR | r4-24-18.monitoring.internet-measurement.com |
| Org / ASN | Constantine Cybersecurity LTD |
| Country | 🇬🇧 United Kingdom |
| City | Manchester, England |
| Timezone | Europe/London |
Internet ScannerInternet-measurement
Internet measurement research scanner performing systematic surveys of internet-facing services. All unsolicited scanning probes are treated as hostile traffic on this network regardless of stated purpose.
Attack Analysis
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
Reports (2)
| Date | Severity | Description |
|---|---|---|
| 29 Sep 2026 - 10:52 | high | IDS: Database port scan — ET SCAN Suspicious inbound to PostgreSQL port 5432 |
| 12 Sep 2026 - 17:26 | high | IDS: Suricata alert — GPL DNS named version attempt |
EagleEye Intelligence