Significant Threat
IP address 137.184.112.103 is a high-risk address operating from DigitalOcean's ASN 14061 infrastructure in the United States, linked to aggressive hacking activity and targeted IoT/ICS reconnaissance with 2,356 documented abuse reports between November 2025 and August 2026. With a threat level of 8/10 and an activity frequency rating of 8/10, this IP demonstrates persistent, high-volume malicious behavior that warrants immediate defensive action.
The detection profile draws from 20 automated honeypot sensors and shows a sustained attack campaign spanning approximately nine months. The dominant threat classification is general hacking intrusion attempts (19 recent reports), complemented by IoT and industrial control system targeted activity (1 recent report), indicating the operator is actively scanning for vulnerable connected devices alongside conventional server-side exploitation attempts. The 86% confidence score reflects substantial corroboration across multiple independent detection sources, making this IP reputation data highly reliable for blocking decisions.
This combination of threat categories presents distinct risks to exposed services. General hacking activity encompasses brute-force authentication attempts, vulnerability scanning, and exploitation probing against server software. The IoT and ICS targeting dimension suggests systematic reconnaissance of smart devices, networked cameras, routers, and industrial equipment with weak security configurations, potentially mapping entry points for botnet recruitment or targeting operational technology environments. The use of a cloud-hosted DigitalOcean IP for this activity enables rapid IP rotation and obfuscation, making timely blocking essential.
Network defenders should block this IP address at perimeter firewalls and implement fail2ban or equivalent rate-limiting rules to interrupt repeated connection patterns. Organizations with IoT deployments should verify network segmentation isolating connected devices from critical infrastructure, confirm firmware is current, and ensure default credentials have been changed. Regular review of authentication logs for source IP 137.184.112.103 will help identify any successful access attempts requiring incident response escalation.