Critical Alert
IP 91.92.40.66, registered to TechTies Inc. under ASN AS197170 in Bulgaria, is a critical-risk address with a threat level of 10/10 and a 94% confidence score, supported by approximately 1,000 abuse reports filed between June and August 2026. The dominant threat category detected across automated honeypot sensors is IoT-targeted activity, representing the largest single category of reported malicious behaviour originating from this address.
The volume and consistency of reports indicate sustained, purposeful scanning and exploitation attempts rather than opportunistic or incidental traffic. With an activity frequency rating of 8/10 and detection across 20 separate honeypot sensors, IP 91.92.40.66 demonstrates a methodical approach to identifying vulnerable internet-of-things devices. The address has been actively reported for approximately three months, suggesting a persistent campaign rather than a transient incident. Network registration data points to TechTies Inc. as the accountable entity, though the source of the malicious activity may originate from compromised infrastructure or third-party exploitation.
IoT-targeted attacks exploit weak security controls in smart devices, routers, cameras and other connected hardware that are frequently deployed with default credentials, unpatched firmware or exposed management interfaces. Attackers leveraging addresses like 91.92.40.66 typically conduct systematic scans to identify exposed UPnP ports, Telnet services or weak authentication on IoT devices, subsequently compromising these endpoints to enlist them in botnets, conduct distributed denial-of-service operations or exfiltrate sensitive data. The real-world risk to organisations with poorly segmented IoT deployments is unauthorised network access, lateral movement and data breach.
Organisations should immediately block or rate-limit traffic from this address at the network perimeter and monitor logs for any attempted connections to IoT management interfaces. Network segmentation separating IoT devices from critical infrastructure is essential to limit lateral movement risk. All IoT devices should have default credentials changed, firmware updated regularly and UPnP disabled. Deploying defensive tools such as fail2ban can further reduce the effectiveness of repeated connection attempts from high-risk sources.