Severe Risk
IP 165.154.174.108 is a high-risk address that automated honeypot sensors have flagged as an active attack platform, with 160 total abuse reports filed and a threat level rating of 10 out of 10, indicating it poses a severe risk to any exposed network service. The IP is geolocated to the United Kingdom and operates within AS135377 under the infrastructure ownership of UCLOUD INFORMATION TECHNOLOGY HK LIMITED, a hosting provider whose network is being actively misused. The dominant threat signature involves general hacking activity, including intrusion attempts and exploitation of vulnerabilities, alongside one confirmed report classifying this address as an exploited host being used as an attack vehicle without the owner's knowledge.
Detection data shows 20 separate automated honeypot sensors across the network recorded this IP connecting to target systems, with the earliest report dating to November 2025 and the most recent in May 2026. The activity frequency has been assessed at 3 out of 10, suggesting the address is not operating at maximum throughput but remains persistently active over approximately six months. Network inspection detected a Suricata intrusion detection signature firing on malformed TLS traffic — specifically an invalid record type — which the sensor classified as consistent with malware or exploit tool communication attempting to establish covert command-and-control channels or deliver malicious payloads. With a confidence score of 75%, analysts assess this threat profile as credible and actionable for immediate defensive response.
The dual classification of this IP as both a hacking source and an exploited host reveals a compound threat scenario. When an attacker compromises a system and uses it as a launchpad, the legitimate owner remains unaware their infrastructure is weaponized against third parties. The TLS protocol anomalies indicate that whatever tools or malware are operating through this address are attempting to disguise their traffic as legitimate encrypted web sessions, making traditional port-blocking alone insufficient. Any service exposing SSH, RDP, HTTP interfaces or unpatched applications to this IP address risks being scanned, brute-forced or targeted with exploit payloads matching the observed hacking pattern signature.