Report for IP: 205.209.102.38

Threat LevelHIGH51/1001 rule type
4 incidents on record · active over 4 days · seen 18h ago
PTR N/A
Org / ASN Host Department NJ, LLC
Country 🇺🇸 United States
City Englewood Cliffs, New Jersey
Timezone America/New_York

Attack Analysis

IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.

Reports (4)

Date Severity Description
29 Sep 2026 - 06:48 high IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306
29 Sep 2026 - 04:59 high IDS: Database port scan
25 Sep 2026 - 05:56 high IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306
24 Sep 2026 - 20:02 high IDS: Database port scan