Check an IP Address, Domain Name, Subnet, or ASN
181.209.63.42 has a threat confidence score of 61%. This IP address from Argentina (AS52361, Empresa Argentina de Soluciones Satelitales S.A.) has been observed in 3 honeypot sessions targeting POSTGRES protocols. First observed on March 19, 2026, most recently active March 19, 2026.
Identifies a PostgreSQL reconnaissance sequence where an actor first issues a comment-based parser probe, then interacts using a deterministic statement-cache prepared statement identifier, followed by enumeration of the current database encoding and locale settings via pg_catalog.pg_database. This pattern reflects automated client or adversarial tooling performing environment fingerprinting to assess query parsing behavior, driver compatibility, and database configuration prior to further interaction or exploitation attempts.