Check an IP Address, Domain Name, Subnet, or ASN
47.84.196.172 has a threat confidence score of 73%. This IP address from Singapore (AS45102, Alibaba US Technology Co., Ltd.) has been observed in 19 honeypot sessions targeting TELNET, SSH, REDIS, ELASTICSEARCH, FTP and 1 other protocols. First observed on February 14, 2026, most recently active March 1, 2026.
Enumerates MongoDB server metadata and storage characteristics across multiple databases by issuing commands such as buildInfo, serverStatus, hostInfo, features, and isMaster, followed by systematic dbStats and collStats queries against common databases including admin, config, local, test, and production. This behavior reflects structured reconnaissance intended to map server capabilities, deployment topology, and data footprint prior to potential follow-on actions.
Client first performs a generic request to the Elasticsearch root endpoint to verify service availability, then proceeds to request /_cat/indices. This sequence reflects staged Elasticsearch reconnaissance where the actor validates that the cluster is reachable before attempting index enumeration and data exposure assessment. Compared to direct index enumeration behaviors, the interaction begins with a service-validation step, suggesting adaptive probing rather than immediate Elasticsearch-specific targeting.