Threat LevelCRITICAL80/1003 rule types across 3 attack categories
7 incidents on record · 3 rule types · confirmed on global blocklist · persistent 14-day campaign · last seen 7d ago · bulletproof hosting
| PTR | N/A |
| Org / ASN | Feo Prest SRL |
| Country | 🇩🇪 Germany |
| City | Aachen, North Rhine-Westphalia |
| Timezone | Europe/Berlin |
Iranian Attack InfrastructureFEO PREST SRL (Iran)
This IP originates from an Iranian netblock (FEO PREST SRL range) that is among the most heavily reported attack infrastructure in global threat databases, with adjacent IPs accumulating over 326,000 independent abuse reports and 100% abuse confidence ratings. The scale and duration of abuse is consistent with state-adjacent or professionally-operated Iranian offensive infrastructure targeting servers globally.
Attack Analysis
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
Port 22 Honeypot Probe
This IP connected to a fake SSH honeypot — a port 22 listener that is not a real SSH server. This is an automated scanner fingerprinting targets before launching a brute-force campaign. Legitimate systems never probe port 22 without a specific reason; this activity is virtually 100% malicious.
Reports (7)
| Date | Severity | Description |
|---|---|---|
| 22 Sep 2026 - 20:02 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 22 Sep 2026 - 20:02 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 9 Sep 2026 - 01:06 | high | IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306 |
| 9 Sep 2026 - 01:06 | high | IDS: Database port scan — ET SCAN Suspicious inbound to PostgreSQL port 5432 |
| 9 Sep 2026 - 01:06 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 9 Sep 2026 - 01:06 | high | IDS: Database port scan — ET SCAN Suspicious inbound to Oracle SQL port 1521 |
| 9 Sep 2026 - 01:06 | high | IDS: Database port scan — ET SCAN Suspicious inbound to MSSQL port 1433 |
EagleEye Intelligence