Critical Threat
IP 163.172.105.163 is a critical-risk address with 236 total abuse reports and a maximum threat score of 10/10, making it one of the most actively malicious IPs currently tracked in public repositories. All recent reported activity falls under the hacking category, indicating sustained intrusion attempts originating from this French infrastructure. Automated honeypot sensors detected this address repeatedly during October 2025, confirming coordinated hostile activity.
Security databases contain 236 total reports for 163.172.105.163, with 20 recent reports specifically categorizing the activity as hacking attempts. Detection originated exclusively from automated honeypot infrastructure, yielding a confidence score of 64% against the IP's maximum threat rating. The address is geolocated in France and operates within AS12876, the autonomous system number assigned to Scaleway S.a.s., a major European cloud and hosting provider. All reported activity occurred within a single month, suggesting either a concentrated short-term campaign or a newly flagged persistent threat.
The hacking classification encompasses various intrusion techniques, including exploitation attempts against known vulnerabilities, unauthorized access attempts against exposed services, and scanning activity designed to identify entry points into target systems. This IP's routing through Scaleway's infrastructure is significant because cloud hosting providers frequently serve as launch points for automated attacks due to their high-bandwidth connections and relative anonymity. The 64% confidence score indicates some uncertainty in attribution, which is common when dealing with dynamic or spoofed source addresses, yet the 10/10 threat level confirms the activity poses genuine risk to exposed services.
Organizations running publicly accessible services should implement immediate defensive measures. Deploying intrusion detection systems capable of identifying scanning and exploitation patterns provides real-time visibility into this IP's behavior. Implementing robust authentication mechanisms—including certificate-based authentication, multi-factor verification, and strong password policies—substantially reduces successful intrusion risk. Rate limiting and automated blocking based on repeated failed authentication attempts (commonly managed through tools like fail2ban) effectively neutralize brute-force campaigns. Regular security monitoring combined with timely patch management for all internet-facing systems closes the vulnerability window that such hacking activity typically exploits.