Severe Risk
IP 164.92.149.146 is a critical-risk Netherlands-based address with a threat level of 10/10 that has generated 1028 abuse reports, primarily linked to sustained hacking activity targeting vulnerable services worldwide. Despite its DigitalOcean cloud-infrastructure origin, the volume and consistency of malicious traffic detected from this address over December 2025 warrant immediate blocking at network perimeters.
The address, registered to DigitalOcean's AS14061 autonomous system, was first and last reported in December 2025, with all 1028 incidents sourced from automated honeypot sensors distributed across multiple networks. The dominant threat category recorded is general hacking activity, encompassing unauthorized access attempts and exploitation of known vulnerability patterns. While the activity frequency metric registers at 0/10, the sheer number of independent detection events indicates persistent scanning and attack behaviour rather than isolated probes. The 59% confidence score reflects that while threat indicators are strong, some report classification ambiguity exists in the source data.
Hacking activity of this nature typically involves systematic attempts to identify and compromise exposed services running outdated software, misconfigured authentication mechanisms, or known vulnerable configurations. Automated honeypot sensors in this case recorded repeated connection attempts consistent with reconnaissance and exploitation tooling, suggesting the address participates in coordinated scanning campaigns or functions as a pivot point for broader intrusion operations. The DigitalOcean origin is notable because cloud-provider IP ranges are frequently repurposed by threat actors for anonymised operations due to their reputation for lenient abuse handling and high-bandwidth connectivity.
Network operators should block 164.92.149.146 at the firewall level and implement geolocation-based restrictions to prevent Netherlands-originated connections to non-essential services. Deploying fail2ban or equivalent log-analysis tools to auto-ban repeat offenders from this address range will reduce log noise and prevent credential-stuffing campaigns. Enforcing multi-factor authentication on all externally accessible interfaces, maintaining strict patch cycles, and monitoring authentication logs for the signature patterns recorded by honeypot sensors will substantially reduce exposure to the exploitation vectors this address attempts to leverage.