Check an IP Address, Domain Name, Subnet, or ASN
64.89.163.81 has a threat confidence score of 93%. This IP address from United Kingdom (AS401626, Netiface America, Inc.) has been observed in 2,824 honeypot sessions and reported 5 times targeting POSTGRES protocols. First observed on February 10, 2026, most recently active May 7, 2026.
Represents a minimal but deliberate PostgreSQL reconnaissance pattern where a client starts an explicit transaction and immediately queries the size of the default postgres database. This behavior is characteristic of automated probes or lightweight bots performing environment valuation, checking whether the target database is non-trivial in size before deciding to continue interaction, escalate activity, or move on. The lack of follow-up queries strongly suggests scripted reconnaissance rather than legitimate application behavior.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| User | Mar 16, 2026, 18:45 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Mar 16, 2026, 03:40 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Mar 14, 2026, 24:04 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Mar 1, 2026, 16:45 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Feb 26, 2026, 03:05 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |