Threat LevelCRITICAL72/1003 rule types across 3 attack categories
6 incidents on record ยท 3 rule types ยท active attacker + blocklisted ยท last seen 5d ago
| PTR | N/A |
| Org / ASN | Secure Internet LLC |
| Country | ๐ฌ๐ง United Kingdom |
| City | City of London, England |
| Timezone | Europe/London |
Attack Analysis
IDS: Blocklist โ Spamhaus DROP
This IP is on the Spamhaus DROP list โ a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour โ including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (6)
| Date | Severity | Description |
|---|---|---|
| 26 Jul 2026 - 16:22 | medium | IDS: Suricata alert โ Honeypot: probe to closed SSH port 22 |
| 26 Jul 2026 - 16:22 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 42 |
| 26 Jul 2026 - 13:30 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 42 |
| 26 Jul 2026 - 13:30 | high | IDS: Database port scan โ ET SCAN Suspicious inbound to mySQL port 3306 |
| 26 Jul 2026 - 04:32 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 42 |
| 25 Jul 2026 - 20:05 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 42 |
EagleEye Intelligence