Check an IP Address, Domain Name, Subnet, or ASN
163.5.102.3 has a threat confidence score of 48%. This IP address from France (AS2914, NTT America, Inc.) has been observed in 4 honeypot sessions targeting POSTGRES protocols. First observed on April 17, 2026, most recently active April 17, 2026.
Represents a minimal but deliberate PostgreSQL reconnaissance pattern where a client starts an explicit transaction and immediately queries the size of the default postgres database. This behavior is characteristic of automated probes or lightweight bots performing environment valuation, checking whether the target database is non-trivial in size before deciding to continue interaction, escalate activity, or move on. The lack of follow-up queries strongly suggests scripted reconnaissance rather than legitimate application behavior.