Substantial Risk
IP 145.239.10.137 is a high-risk address operated by OVH SAS in France that has accumulated 178 abuse reports over approximately eight months, with web application attack probes accounting for its most recent confirmed activity. The threat level has been assessed at 10 out of 10, reflecting sustained malicious behaviour detected across automated honeypot infrastructure. This IP warrants immediate blocking for any organization running publicly accessible web services.
Detection data shows 20 separate automated honeypot sensors flagged this address engaging in web application reconnaissance and probing activity. The reports span from September 2025 through May 2026, indicating persistent rather than transient malicious intent. The activity frequency rating of 4 out of 10 suggests moderate but consistent engagement with target systems over time. The 76% confidence score reflects the reliability of the classification given the volume of independent sensor reports and the clear pattern of web-focused attack behaviour. OVH SAS, operating AS16276, is a large European hosting provider whose network is frequently abused by threat actors due to its scale and permissive onboarding practices.
Web application attacks represent a broad category of exploitation attempts targeting software vulnerabilities commonly found in internet-facing applications. The probing patterns observed suggest this address is systematically testing for weaknesses such as injection flaws, authentication bypasses, and misconfigured server settings that fall under the OWASP Top 10 classification. Successful exploitation of these vulnerabilities can result in data breaches, server compromise, or pivoting to internal network resources. The scale of reporting activity indicates this IP is part of automated scanning infrastructure rather than opportunistic manual probing.
Administrators managing public-facing web applications should treat this IP as explicitly hostile and implement defensive controls accordingly. Deploying a web application firewall with updated rule sets will detect and block probing patterns before they reach application logic. Rate-limiting incoming requests and enforcing strong authentication on administrative interfaces reduces the effectiveness of enumeration attempts. Fail2ban or equivalent host-based intrusion prevention tools can parse honeypot-generated logs and automatically update firewall rules. Regular security audits and prompt patching of application dependencies eliminate the vulnerabilities such scanners target, ensuring that even if connection attempts succeed, exploitation cannot follow.