Critical Alert
IP 4.145.113.4 is a high-risk address originating from Singapore that has been linked to sustained hacking activity, accumulating 1,642 abuse reports across automated honeypot sensors over approximately ten months with a threat level of 10/10 and a confidence score of 94 percent. This IP represents one of the most actively reported addresses in recent threat-intelligence collections, with an activity frequency rating of 8/10 indicating persistent rather than intermittent malicious behavior.
The reporting window spans from September 2025 through July 2026, with all 1,642 reports attributed to automated honeypot detections of hacking activity. The address is routed through AS8075 (MICROSOFT-CORP-MSN-AS-BLOCK), a Microsoft-managed ASN commonly associated with cloud infrastructure in the Singapore region. The consistent volume of reports over this extended timeframe, combined with the high confidence rating, suggests this is not opportunistic scanning but rather sustained, targeted intrusion activity directed at accessible network services.
Hacking activity encompasses a broad range of intrusion attempts including exploitation of vulnerabilities, unauthorized access attempts, and generic attack connections targeting exposed services. For organizations running publicly accessible SSH, Telnet, HTTP, or database services, an IP with this reputation poses concrete risks of credential compromise, data exfiltration, or establishment of persistent footholds within internal networks. The sustained nature of the activity over many months indicates the operator is systematically probing or repeatedly engaging with target systems.
Site operators should immediately block IP 4.145.113.4 at the network perimeter firewall and implement automated blocking via security tools such as fail2ban or equivalent threat-responsive solutions. Rate-limiting incoming connections to critical services will reduce the effectiveness of repeated intrusion attempts. Ensuring all exposed services run current patches and enforce strong, non-default authentication credentials eliminates common exploitation vectors. Continuous monitoring of authentication logs for unusual patterns originating from this address range will help identify any successful compromise attempts that may bypass initial defensive layers.