Critical Alert
IP 168.110.195.99 is a critical-risk address that security monitoring systems have flagged for active hacking activity, with a threat level rated at the maximum 10 out of 10 and a 94 percent confidence score indicating the malicious intent is highly certain.
Network telemetry data shows that 218 separate abuse reports have been logged against this IP address originating from Indonesia and routed through Oracle Corporation's autonomous system AS31898. The address was first reported in May 2026 and remained active through June 2026, demonstrating a sustained campaign of approximately two months. All 218 reports were generated by automated honeypot sensors designed to capture and analyze hostile network traffic, and the activity frequency score of 8 out of 10 confirms consistent, repeated probing rather than isolated or opportunistic scanning.
The dominant threat category for IP 168.110.195.99 is general hacking activity, which encompasses unauthorized intrusion attempts, vulnerability exploitation and brute-force credential attacks against exposed services. With 218 reports concentrated within a two-month window, this IP has demonstrated systematic scanning behavior targeting network edge devices and services that may contain unpatched software or misconfigured authentication mechanisms. The real-world risk is direct compromise of affected systems, potential data exfiltration and the establishment of persistent access for subsequent attack stages.
Site operators should immediately block or rate-limit connections from this IP at the network perimeter firewall and implement geolocation-based restrictions if Indonesian traffic is not expected. Deploying or strengthening brute-force mitigation tools such as fail2ban or equivalent authentication-failure lockout policies will reduce the effectiveness of credential-guessing attempts. Maintaining rigorous patch management schedules and intrusion detection monitoring will further harden exposed services against the exploitation techniques associated with this address. Regular review of network-level abuse reports and integration of IP reputation feeds will provide ongoing protection against similar threats.