Elevated Risk
IP 135.237.125.143 is a high-risk address assessed at 8/10 threat level, operated within Microsoft-Corp-MSN-AS-Block infrastructure in the United States, with 233 abuse reports across 20 automated honeypot sensors documenting sustained malicious activity spanning from September 2025 through June 2026. The dominant threat category is general hacking activity, supported by strong indicators of an exploited host being leveraged for reconnaissance and potentially financial fraud. With a confidence score of 65% and activity frequency rated at 4/10, this IP presents a concrete, ongoing risk to exposed network services. The report volume and timeframe indicate persistent rather than opportunistic behavior, making this address unsuitable for whitelisting or trust placement in any security posture. Network defenders should treat 135.237.125.143 as a confirmed malicious actor until evidence suggests otherwise.
The 233 total reports submitted against 135.237.125.143 break down across four threat categories: Hacking (13 reports), Exploited Host (5 reports), Port Scan (4 reports), and Fraud VoIP (1 report). The honeypot sensor data reveals consistent attack patterns including Suricata-detected port scans using Zmap user-agent strings, which are characteristic of automated reconnaissance campaigns designed to map exposed services and identify vulnerabilities. The presence of both malware/exploit activity flags and VoIP fraud indicators alongside the scanning behavior suggests this compromised system may be part of a larger coordinated operation or botnet activity. The fact that this IP originates from AS8075, a major Microsoft cloud infrastructure block, is particularly significant — cloud-hosted attack platforms often benefit from high-bandwidth connectivity and IP reputations that temporarily evade basic blocklists, prolonging their effectiveness before detection.
The threat profile for 135.237.125.143 reflects a classic exploited-host scenario where a compromised or misconfigured cloud resource is being weaponized by threat actors without the legitimate owner's knowledge. The port scanning activity specifically targets inbound connections using Zmap, an efficient network mapping tool commonly employed to rapidly discover open ports across large IP ranges before launching targeted exploits. Combined with VoIP fraud indicators, this suggests the compromised system may be harvesting network intelligence for telephony-based scams or serving as a relay point for fraudulent calls. The hacking classification encompasses the broader exploitation attempts and intrusion activity captured by honeypot sensors, indicating this IP has actively attempted to compromise services rather than simply probing them. Organizations with exposed SSH, RDP, VoIP, or web-facing services should treat any connection from this address as hostile.