High Risk
165.227.110.45 is a high-risk address associated with sustained malicious activity, generating 2,524 abuse reports across automated honeypot sensors over approximately one year. This DigitalOcean-hosted US IP presents a threat level of 8/10 and demonstrates persistent engagement in hacking operations and exploited-host behavior that poses a concrete danger to any exposed service.
The IP's activity profile shows 2,524 reported incidents since September 2025, with the most recent reports filed in August 2026, indicating continuous operation over an eleven-month window. Detection was achieved through 20 automated honeypot sensors that flagged patterns consistent with unauthorized intrusion attempts and system exploitation. The address operates within AS14061 (DIGITALOCEAN-ASN), a widely-used cloud hosting network that threat actors frequently abuse both as targets and launch platforms. The dominant reported category is hacking (19 incidents), with a smaller subset of exploited-host reports (1 incident) suggesting the IP may itself be a compromised asset running malicious tooling without its operator's knowledge.
The hacking classification encompasses automated intrusion attempts, vulnerability exploitation, and unauthorized access campaigns that systematically probe public-facing services for weaknesses. The presence of malware and exploit activity patterns indicates this address participates in campaigns designed to compromise remote systems, potentially deploying additional payloads or establishing persistent access. When combined with the exploited-host designation, this suggests the IP functions both as an active attacker and potentially as a node within a broader attack infrastructure, compounding the risk it poses to any organization with direct network exposure.
Site operators should block this address at the firewall level or via intrusion-prevention tools such as fail2ban to immediately sever hostile connection attempts. Strengthening authentication on exposed services—enforcing key-based authentication, enforcing strong password policies, and implementing multi-factor authentication where supported—significantly reduces the viability of credential-based intrusion. Maintaining strict patching cycles for all public-facing software eliminates the vulnerabilities such actors typically exploit. Organizations discovering sustained contact from this address should also consider filing an abuse report with DigitalOcean to alert the provider to potential compromise of infrastructure within its network.