Report for IP: 192.253.248.92

Threat LevelCRITICAL72/1003 rule types across 3 attack categories
6 incidents on record ยท 3 rule types ยท active attacker + blocklisted ยท last seen 5d ago
PTR N/A
Org / ASN Secure Internet LLC
Country ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
City City of London, England
Timezone Europe/London

Attack Analysis

๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands ยท Kerkrade ยท 213790 ยท Secure Internet LLC
IDS: Blocklist โ€” Spamhaus DROP
This IP is on the Spamhaus DROP list โ€” a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour โ€” including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (6)

Date Severity Description
26 Jul 2026 - 16:22 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
26 Jul 2026 - 16:22 high IDS: Blocklist โ€” Spamhaus DROP listed IP โ€” ET DROP Spamhaus DROP Listed Traffic Inbound group 42
26 Jul 2026 - 13:30 high IDS: Blocklist โ€” Spamhaus DROP listed IP โ€” ET DROP Spamhaus DROP Listed Traffic Inbound group 42
26 Jul 2026 - 13:30 high IDS: Database port scan โ€” ET SCAN Suspicious inbound to mySQL port 3306
26 Jul 2026 - 04:32 high IDS: Blocklist โ€” Spamhaus DROP listed IP โ€” ET DROP Spamhaus DROP Listed Traffic Inbound group 42
25 Jul 2026 - 20:05 high IDS: Blocklist โ€” Spamhaus DROP listed IP โ€” ET DROP Spamhaus DROP Listed Traffic Inbound group 42