Summary (Bottom Line Up Front)
IP address 185.247.137.238 conducted sustained reconnaissance targeting industrial control systems and database services over a 72-day period from February 12 to April 24, 2026. The threat actor employed multi-protocol scanning techniques including Siemens S7COMM, Oracle TNS, and Modbus protocols, indicating potential targeting of critical infrastructure environments. Organizations operating industrial control systems should implement immediate monitoring and access controls for affected protocols. ##
Activity Timeline
UPDATE 22026-04-24T15:45:49Z
Source: Analyst Manual Entry
IP address 185.247.137.238 conducted sustained reconnaissance targeting industrial control systems and database services over a 72-day period from February 12 to April 24, 2026. The threat actor employed multi-protocol scanning techniques including Siemens S7COMM, Oracle TNS, and Modbus protocols, indicating potential targeting of critical infrastructure environments. Organizations operating industrial control systems should implement immediate monitoring and access controls for affected protocols.
New findings
Attack Profile: 56 reconnaissance events targeting 10 unique destination ports across industrial and enterprise protocols including EtherNet/IP, S7COMM, Modbus, PostgreSQL, and Oracle TNS. Primary techniques aligned with MITRE T1046 (Network Service Scanning) during the reconnaissance phase of the kill chain. Notable payload samples included Oracle TNS version enumeration attempts ("CONNECT_DATA=(COMMAND=version") and generic internet measurement scanning activities. Attack patterns demonstrated medium-severity industrial control system probing and database service enumeration, with no evidence of exploitation attempts or zero-day usage.
Indicators of Compromise:
- Source IP: 185.247.137.238
- Targeted Protocols: S7COMM (port 102), Oracle TNS, Modbus, EtherNet/IP
- Campaign Duration: February 12, 2026 06:00 - April 24, 2026 08:00
- Attack Signature: Non-TPKT formatted S7COMM traffic, TNS version enumeration
Recommendations
- Block IP address 185.247.137.238 at network perimeters and implement monitoring for similar reconnaissance patterns targeting industrial protocols
- Audit and restrict access to industrial control system ports (102/S7COMM, 502/Modbus, 44818/EtherNet-IP) ensuring proper network segmentation
- Deploy enhanced logging and alerting for Oracle TNS version enumeration attempts and unusual database connection patterns
- Conduct immediate asset inventory of exposed industrial control systems and database services accessible from internet-facing networks
- Implement protocol-aware deep packet inspection for industrial control system traffic to detect malformed or reconnaissance packets
UPDATE 12026-04-24T13:38:19Z
Source: Analyst Manual Entry
Threat actor 185.247.137.238 conducted sustained reconnaissance targeting industrial control systems and enterprise services over a 71-day period from February 12 to April 24, 2026. The campaign focused on critical infrastructure protocols including Siemens S7COMM, Oracle TNS, and Modbus systems with 56 observed scanning events. Organizations operating industrial control systems should immediately review network segmentation and implement enhanced monitoring for these protocols.
New findings
Attack Profile: Multi-protocol reconnaissance campaign targeting industrial and enterprise infrastructure
Duration: 71 days (February 12 06:00 - April 24 08:00, 2026)
Volume: 56 events across 10 unique destination ports
Primary Protocols: S7COMM (Siemens industrial), Oracle TNS, Modbus, HTTP/HTTPS, PostgreSQL
MITRE Technique: T1046 (Network Service Scanning)
Kill Chain Phase: Reconnaissance
Key Indicators: Non-TPKT formatted S7COMM traffic on port 102, Oracle TNS version enumeration attempts, generic scanning user agents
Payload Samples: Oracle TNS connection strings containing "COMMAND=version", HTTP requests with "InternetMeasurement" user agent
Recommendations
- Implement network segmentation to isolate industrial control systems from internet-facing networks and restrict access to ports 102 (S7COMM), 502 (Modbus), and 1521 (Oracle TNS)
- Deploy protocol-aware monitoring for industrial control system communications to detect anomalous or malformed traffic patterns
- Review and harden Oracle TNS configurations, disable version disclosure, and implement connection filtering
- Establish baseline traffic patterns for industrial protocols and alert on deviations or unexpected connection attempts
- Conduct immediate asset inventory of exposed industrial control systems and database services accessible from external networks
INITIAL REPORT2026-04-21T14:52:17Z
Source: Analyst Manual Entry
External threat actor 185.247.137.238 conducted sustained reconnaissance against industrial control systems and enterprise services over 68 days, targeting Siemens S7COMM, Oracle TNS, and other critical protocols. This represents MEDIUM-severity threat activity focused on infrastructure enumeration that could enable future attacks against operational technology environments. Organizations should immediately review ICS network segmentation and implement enhanced monitoring for industrial protocol abuse.
Technical details
Attack Vector: Multi-protocol reconnaissance campaign targeting industrial and enterprise systems
Duration: February 12, 2026 06:00 - April 21, 2026 00:00 (68 days active)
Volume: 56 events across 10 unique destination ports
Protocols Targeted: Siemens S7COMM (port 102), Oracle TNS, Modbus, EtherNet/IP, PostgreSQL, HTTP/HTTPS with TLS variants
MITRE Technique: T1046 (Network Service Scanning)
Key Indicators: Non-TPKT formatted traffic to S7 industrial protocol ports, Oracle TNS version enumeration attempts, automated scanning signatures including "InternetMeasurement" user agent
Threat Classification: Reconnaissance phase activity with focus on critical infrastructure discovery
IOCs
IP:185.247.137.238
Recommendations
- Implement network segmentation to isolate industrial control systems from internet-facing networks and restrict S7COMM, Modbus, and EtherNet/IP protocols to authorized internal communications only
- Deploy industrial protocol-aware monitoring solutions to detect anomalous traffic patterns on ports 102 (S7), 502 (Modbus), and 44818 (EtherNet/IP)
- Block source IP 185.247.137.238 at perimeter firewalls and review logs for any successful connections to industrial or database services
- Conduct security assessment of Oracle TNS services to ensure proper authentication controls and network exposure limitations are in place
- Enable enhanced logging for industrial protocol communications and establish baseline traffic patterns to identify future reconnaissance attempts