Extreme Threat
IP 103.250.85.149 is a critical-risk address originating from India that has been flagged 171 times by automated honeypot sensors over approximately five months, with 20 of the most recent reports classifying it as an exploited host actively conducting hacking activity. The IP's threat level scores 10 out of 10, reflecting an assessment that it poses severe risk to any exposed services. The dominant detected behavior involves SMBv1 protocol activity, a legacy file-sharing mechanism known for being leveraged in numerous severe exploits. This combination of high report volume, exploited-host classification, and evidence of potentially dangerous protocol usage makes IP 103.250.85.149 a priority candidate for blocking across any internet-facing infrastructure.
Detection data indicates that 20 separate automated honeypot sensors registered activity from 103.250.85.149 between November 2025 and April 2026, representing a sustained presence over roughly five months. The network is operated by B TEL INTERNET PRIVATE LIMITED (ASN AS58765) within Indian IP space, and the confidence score of 59 percent suggests moderate certainty in the current classification, leaving room for the possibility that the host itself may be a compromised platform rather than an intentionally malicious actor. The activity frequency metric of 0 out of 10 is notable, as it may indicate sporadic or burst-oriented engagement with honeypot sensors rather than continuous probing. Suricata alerts specifically flagged potentially unsafe SMBv1 protocol usage on multiple occasions, a pattern consistent with exploitation toolkit activity or lateral movement attempts.
The classification of 103.250.85.149 as an exploited host suggests that the underlying system has likely been compromised by threat actors and is now being weaponized without the knowledge of its legitimate operator. When combined with the detected SMBv1 activity, this pattern indicates that the IP may be part of a botnet or compromised infrastructure being used to scan for vulnerable systems, propagate malware, or execute remote code against targets running outdated Windows file-sharing services. The hacking activity logged alongside the exploited-host classification further reinforces that the IP is engaged in intrusion attempts, vulnerability exploitation, or unauthorized access operations. Organizations with exposed SMB services face particular risk from this address, as SMBv1 vulnerabilities have historically underpinned devastating attacks including ransomware propagation and remote code execution.