Loading threats
Client repeatedly requests MongoDB startup warnings using the getLog command and disconnects shortly after. This pattern indicates automated inspection of server diagnostics to gather environment details, commonly seen during discovery or reconnaissance against exposed MongoDB services.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 47.109.204.89 | 87% | 446 | 370 | 🇨🇳 CN | AS37963 | 2026-03-16 |
| 100.27.169.19 | 78% | 303 | 209 | 🇺🇸 US | AS14618 | 2026-03-16 |
| 148.223.224.70 | 72% | 138 | 126 | 🇲🇽 MX | AS8151 | 2026-03-16 |
| 140.143.250.169 | 63% | 123 | 67 | 🇨🇳 CN | AS45090 | 2026-02-20 |
| 49.36.33.230 | 63% | 97 | 10 | 🇮🇳 IN | AS55836 | 2026-02-20 |
| 139.186.178.91 | 59% | 64 | 40 | 🇨🇳 CN | AS45090 | 2026-03-13 |
| 13.57.74.238 | 48% | 53 | 32 | 🇺🇸 US | AS16509 | 2026-02-14 |
| 18.213.252.175 | 55% | 48 | 31 | 🇺🇸 US | AS14618 | 2026-03-14 |
| 13.209.107.124 | 58% | 42 | 30 | 🇰🇷 KR | AS16509 | 2026-03-12 |
| 54.238.91.29 | 55% | 41 | 23 | 🇯🇵 JP | AS16509 | 2026-03-04 |
| 13.235.11.255 | 56% | 35 | 16 | 🇮🇳 IN | AS16509 | 2026-02-22 |
| 13.62.108.97 | 61% | 34 | 16 | 🇸🇪 SE | AS16509 | 2026-02-14 |
| 52.27.208.231 | 53% | 28 | 16 | 🇺🇸 US | AS16509 | 2026-03-10 |
| 46.137.234.118 | 52% | 24 | 14 | 🇸🇬 SG | AS16509 | 2026-02-23 |
| 13.251.230.154 | 51% | 24 | 12 | 🇸🇬 SG | AS16509 | 2026-02-26 |