Critical Alert
IP 78.153.140.40 is a high-risk address associated with web application attack probes, detected extensively by automated honeypot sensors over approximately nine months of sustained activity. With a threat level of 10 out of 10 and an activity frequency rated 8 out of 10, this IP has generated 688 total abuse reports, indicating persistent and aggressive scanning behavior targeting web-facing applications.
The detection data shows all recent reported threat categories — 20 instances — are classified as Web App Attacks, sourced from 20 separate automated honeypot sensors. The IP originates from the United Kingdom and operates through AS202306, managed by Hostglobal.plus Ltd. The first report dates to August 2025, with continued reporting through May 2026, demonstrating a sustained campaign rather than a brief opportunistic scan. The confidence score of 59% reflects the automated nature of the detections without additional manual attribution data.
Web application attacks encompass exploitation attempts against vulnerabilities such as cross-site scripting, SQL injection, file inclusion, and other OWASP Top 10 weaknesses. An IP conducting persistent probing at this frequency indicates automated vulnerability scanning, likely seeking unpatched or misconfigured web servers for subsequent exploitation. The real-world risk is direct: exposed web applications may be compromised, leading to data theft, website defacement, or pivoting into internal networks. Even failed probes confirm the presence of an attacker actively mapping your attack surface.
Site operators should act immediately by deploying a web application firewall to filter malicious request patterns, blocking or rate-limiting this IP at the network perimeter. Enforcing strong authentication, including multi-factor authentication, on all administrative interfaces reduces the impact of successful access. Regular security audits and prompt patching of web application software eliminate the vulnerabilities this scanner targets. Monitoring authentication logs for brute-force patterns and implementing defensive tools such as fail2ban can further reduce exposure to automated reconnaissance.