Severe Risk
IP 144.172.108.231 is a critical-risk address originating from the United States under network operator ROUTERHOSTING (AS14956), carrying a maximum threat score of 10/10 and accumulating 5,905 total abuse reports tied to general hacking activity. Despite a substantial historical report volume, this IP has shown no recorded activity frequency in recent windows, suggesting either a cessation of operations, successful takedown, or shift to alternative infrastructure by the threat actor controlling it.
Analysis of the 20 most recent honeypot-verified reports confirms that automated honeypot sensors detected sustained intrusion-oriented behavior from this address during October 2025, the only month currently reflected in the available reporting window. The 59% confidence score indicates moderate certainty in the classification, meaning analysts cannot fully rule out misclassification from shared or NATed traffic environments. Nevertheless, the sheer volume of prior reports establishes a clear and persistent threat pattern over time, even as immediate activity has reportedly tapered to zero.
The dominant threat category—hacking—encompasses intrusion attempts, exploitation of known and zero-day vulnerabilities, and unauthorized access probing against exposed services such as SSH, Telnet, HTTP APIs, and database interfaces. For any organization running publicly accessible services, an address with this report history represents a concrete risk of credential brute-forcing, service enumeration, or exploitation of unpatched software. Even at zero current frequency, the historical footprint indicates sophisticated automated tooling that operators should not assume has been permanently retired.
Site administrators are advised to block or aggressively rate-limit traffic from this address at the firewall or load-balancer level. Implementing strong authentication mechanisms—including key-based SSH access, multi-factor authentication for administrative panels, and automated tools such as fail2ban—substantially reduces the effectiveness of intrusion attempts from known abusing IPs. Continuous monitoring of authentication logs for patterns consistent with brute-force or enumeration activity originating from this IP range is also recommended to catch any resumption of operations.