Check an IP Address, Domain Name, Subnet, or ASN
64.89.163.83 has a threat confidence score of 93%. This IP address from United Kingdom (AS401626, Netiface America, Inc.) has been observed in 1,333 honeypot sessions and reported 6 times targeting POSTGRES protocols. First observed on February 11, 2026, most recently active March 17, 2026.
Represents a minimal but deliberate PostgreSQL reconnaissance pattern where a client starts an explicit transaction and immediately queries the size of the default postgres database. This behavior is characteristic of automated probes or lightweight bots performing environment valuation, checking whether the target database is non-trivial in size before deciding to continue interaction, escalate activity, or move on. The lack of follow-up queries strongly suggests scripted reconnaissance rather than legitimate application behavior.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| User | Mar 13, 2026, 07:55 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Mar 11, 2026, 03:54 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Mar 5, 2026, 21:41 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Feb 27, 2026, 20:47 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |
| User | Feb 27, 2026, 12:26 | Brute Force | POSTGRES | SikkerGuard: 2 blocked packets |