Severe Risk
IP 144.172.112.197 is a high-risk address associated with 2,867 reported hacking incidents detected by automated honeypot sensors, representing a critical threat level of 10 out of 10 despite moderate attribution confidence of 59 percent. The IP originates from the United States and operates within AS14956, managed by the network operator ROUTERHOSTING. The dominant threat category logged against this address is general hacking activity, encompassing intrusion attempts, exploitation attempts, and unauthorized access probing against exposed services.
The report volume of 2,867 incidents aggregated from automated honeypot sensors reflects sustained malicious activity concentrated within a single reporting month of November 2025, indicating a focused and intensive campaign rather than distributed low-level scanning. The discrepancy between the maximum threat score and a moderate confidence rating suggests that while the hostile intent is clear, definitive attribution to a specific threat actor or campaign remains limited. The zero activity frequency metric may indicate that the observed activity window concluded, though the sheer volume of historical reports confirms this address poses a concrete, documented danger to any exposed network endpoint.
Hacking activity as recorded against this IP encompasses the broad spectrum of intrusion methodologies, including credential guessing, vulnerability probing, and exploitation attempts against services accessible from the internet. Even with activity frequency appearing to have subsided, the magnitude of prior reports signals that this address was systematically cataloguing and attempting to compromise exposed attack surfaces. Any service with open ports, weak authentication, or unpatched software directly in the path of this IP faces real-world risk of compromise, data exfiltration, or lateral movement within a network.
Site operators should immediately block IP 144.172.112.197 at the firewall or network edge to eliminate any continued probing risk, regardless of apparent activity levels. Deploying fail2ban or equivalent log-based intrusion prevention tools can automatically detect and ban sources generating authentication failure patterns consistent with brute-force or scanning behavior. Enforcing strong, unique credentials alongside multi-factor authentication across all internet-facing services dramatically reduces the effectiveness of intrusion attempts from addresses like this one. Regular monitoring of access logs for this IP address and correlated activity remains essential even after blocking, as adversaries may rotate source infrastructure while maintaining consistent targeting patterns.