Severe Risk
IP 172.93.221.176 is a high-risk address operating from xTom Japan Corporation's AS3258 network in Japan, linked exclusively to active hacking activity with a threat score of 10 out of 10 and a confidence rating of 85 percent.
Security monitoring detected 239 distinct abuse reports originating from 20 separate automated honeypot sensors over a concentrated two-month window from March 2026 through May 2026. This volume translates to an activity frequency rating of 7 out of 10, indicating sustained and persistent intrusion attempts rather than opportunistic scanning. The network's geographic location in Japan places this source within a major internet exchange region, while its autonomous system assignment to xTom Japan Corporation suggests the infrastructure may serve as a relay point for threat actors leveraging servers in East Asia to obscure their origin.
The reported hacking activity includes TCP stream anomalies detected by intrusion-analysis sensors, specifically malformed packet timestamps and unexpected retransmissions that indicate active reconnaissance and protocol exploitation attempts against exposed services. This pattern is consistent with automated tooling designed to fingerprint and exploit vulnerable network configurations, posing a concrete risk of unauthorized access to misconfigured or unpatched systems.
Site operators should block or rate-limit connections from this IP at the network perimeter, enforce strong authentication on any exposed services, and ensure systems remain patched against known vulnerabilities. Deploying tools such as fail2ban can help mitigate automated attacks, and sustained traffic monitoring will be essential to identify any shifts in the observed threat methodology.