Notable Threat
IP 207.90.244.11 is a high-risk address assessed at 8/10 threat level, associated with sustained general hacking activity that generated 3,563 abuse reports across automated honeypot sensors over approximately one year, from September 2025 through August 2026.
With a confidence score of 91% and an activity frequency rated 8/10, this IP has been persistently flagged for intrusion-oriented behavior originating from the Cogent Communications network (AS174) in the United States. The report volume of 3,563 incidents represents a notably high abuse level, indicating continuous automated scanning or exploitation attempts rather than isolated probes. All reported threat categorizations consistently point to general hacking activity, suggesting a coordinated campaign focused on identifying and compromising vulnerable services accessible from the public internet. The detection footprint spans multiple automated honeypot sensors, which together logged activity across the full reporting window, demonstrating that this address has maintained its malicious behavior over an extended period.
General hacking activity encompasses a broad spectrum of intrusion attempts, including vulnerability scanning, exploitation of unpatched services, and repeated attempts to gain unauthorized access to exposed systems. The sustained volume and frequency of reports indicate this IP is actively probing network perimeters at scale, likely as part of an automated botnet or distributed scanning operation. Organizations running publicly accessible services face concrete risk of credential stuffing, exploit attempts against known vulnerabilities, or reconnaissance activity that precedes more targeted attacks if this address is not blocked or aggressively rate-limited.
Site operators should implement network-level blocking of this IP based on available threat intelligence feeds, apply aggressive rate-limiting to authentication endpoints, and ensure all exposed services are patched against known vulnerabilities. Deploying intrusion detection signatures and monitoring for the attack patterns associated with this address will further reduce exposure. Additionally, hardening authentication mechanisms through multi-factor authentication and enforcing strong password policies represents a critical defensive layer against the types of unauthorized access attempts this IP is known to conduct.