Loading threats
Unauthenticated or opportunistic client performs broad MongoDB environment reconnaissance across multiple databases (admin, config, local, production, test) including handshake probing, database statistics gathering, collection enumeration, and bulk document listing of sensitive application datasets (users, sessions, api_keys, payments, orders, secrets, audit logs). Activity escalates to destructive actions via repeated dropDatabase commands and concludes with insertion of a ransom note database (READ_ME_TO_RECOVER_YOUR_DATA). This behavior pattern is characteristic of automated internet-wide MongoDB exploitation campaigns involving data wiping, extortion messaging, and opportunistic post-access reconnaissance.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 64.89.163.132 | 100% | 44,751 | 7,770 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 64.89.163.131 | 100% | 43,386 | 6,555 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 64.89.163.130 | 100% | 40,003 | 7,333 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 45.156.87.10 | 100% | 9,775 | 9,660 | 🇳🇱 NL | AS51396 | 2026-03-19 |
| 64.89.163.86 | 100% | 7,857 | 4,381 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 64.89.163.85 |
| 100% |
| 7,488 |
| 4,855 |
| 🇬🇧 GB |
| AS401626 |
| 2026-03-19 |
| 64.89.163.87 | 100% | 7,191 | 5,328 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 64.89.163.243 | 100% | 4,446 | 4,231 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 176.65.132.93 | 100% | 4,128 | 3,962 | 🇩🇪 DE | AS51396 | 2026-03-19 |
| 176.65.132.141 | 100% | 2,678 | 2,594 | 🇩🇪 DE | AS51396 | 2026-03-19 |
| 45.156.87.252 | 100% | 2,538 | 2,319 | 🇳🇱 NL | AS51396 | 2026-03-19 |
| 176.65.132.39 | 100% | 2,502 | 2,429 | 🇩🇪 DE | AS51396 | 2026-03-19 |
| 185.242.3.71 | 100% | 1,633 | 1,629 | 🇳🇱 NL | AS60223 | 2026-03-19 |
| 45.156.87.119 | 100% | 1,500 | 1,499 | 🇳🇱 NL | AS51396 | 2026-03-19 |
| 45.156.87.7 | 100% | 1,296 | 1,260 | 🇳🇱 NL | AS51396 | 2026-03-19 |
| 64.89.163.245 | 99% | 908 | 797 | 🇬🇧 GB | AS401626 | 2026-03-19 |
| 45.153.34.81 | 100% | 610 | 610 | 🇳🇱 NL | AS51396 | 2026-03-19 |
| 43.228.157.45 | 100% | 597 | 573 | 🇵🇰 PK | AS205759 | 2026-03-19 |
| 64.89.163.244 | 100% | 593 | 593 | 🇬🇧 GB | AS401626 | 2026-03-19 |