Extreme Threat
IP 175.110.122.149 is a maximum-risk address operated by WorldStream B.V. in the Netherlands that has been linked to 532 abuse reports over intensive automated scanning activity targeting internet-of-things infrastructure, with a threat level of 10 out of 10 and a 94 percent confidence score indicating highly reliable attribution.
The IP address, registered to ASN AS49981 operated by WorldStream B.V., generated its 532 reports through 20 distinct automated honeypot sensors, reflecting systematic, distributed scanning rather than isolated probe attempts. Activity was first documented in April 2026 and continued through May 2026, demonstrating sustained persistence over at least a two-month observation window with an activity frequency rated 8 out of 10, indicating near-continuous hostile engagement. The geographic origin in the Netherlands places this traffic within a European hosting environment commonly associated with both legitimate cloud infrastructure and threat actors leveraging jurisdictional privacy considerations.
The dominant threat category of IoT-targeted activity represents automated exploitation attempts against smart devices, routers, cameras and other connected hardware that frequently ship with weak default credentials, unpatched firmware and exposed management interfaces. An attacker operating this IP would systematically probe for vulnerable IoT deployments, potentially compromising devices to recruit them into botnets, exfiltrate sensitive data streams, or pivot through compromised hardware into deeper network segments. The concentration of honeypot detections confirms this is not opportunistic traffic but targeted infrastructure reconnaissance designed to identify and compromise poorly secured connected devices.
Network defenders should immediately block or rate-limit traffic from 175.110.122.149 at the firewall level and monitor for any attempted connections to IoT management ports on internal networks. Organizations with connected devices should segment IoT traffic into isolated network zones using VLANs, replace all default credentials with strong unique passwords, and ensure firmware updates are applied consistently. Implementing intrusion detection rules tuned to anomalous IoT protocol behavior and disabling universal plug-and-play on routers will reduce the attack surface available to this and similar scanning infrastructure. Deploying defensive tools such as fail2ban can further automate the blocking of repeat offenders identified through this pattern of activity.