Critical Threat
IP address 175.110.122.151 is a high-risk Dutch address operated by WorldStream B.V. (ASN AS49981) that presents a severe, confirmed threat with a 10/10 threat level and 94% confidence across 532 abuse reports submitted over April–May 2026. This IP is definitively associated with IoT-targeted exploitation activity, indicating a deliberate, automated campaign against internet-of-things devices and potentially industrial control systems.
The volume and consistency of reporting for this address are striking. All 532 reports originate from automated honeypot sensors, and the most recent batch of 20 reports all flag IoT-targeted activity as the threat category. The activity frequency rating of 8/10 signals sustained, repeated probing behaviour rather than a brief or isolated incident. The two-month reporting window from April to May 2026 demonstrates persistent engagement over a meaningful timeframe. Geographically, the Netherlands-based hosting infrastructure is consistent with many commercial threat actors who leverage bulletproof or semi-compliant hosting providers to conduct global scanning and exploitation campaigns against poorly secured connected devices worldwide.
IoT-targeted attacks exploit the well-documented weaknesses prevalent in smart devices, cameras, routers, sensors, and industrial equipment that often ship with default credentials, unpatched firmware, and exposed management interfaces. A source IP conducting this category of attack is actively scanning or attempting to compromise these devices at scale, either to enlist them in a botnet, exfiltrate data, or pivot into attached networks. For any organisation operating exposed IoT or ICS infrastructure, an IP with this profile represents a concrete and immediate exploitation risk if those devices lack hardening or monitoring.
Network defenders should immediately block or rate-limit traffic from 175.110.122.151 at the perimeter firewall and at any intrusion-prevention systems monitoring internet-facing assets. Organisations with IoT deployments should isolate those segments from core infrastructure using VLANs or dedicated firewalled zones, enforce strong, non-default credentials on all connected devices, and ensure firmware is kept current. Implementing fail2ban or equivalent log-analysis tools to automatically block repeated exploitation patterns is strongly advised. Continuous monitoring of inbound connection logs for this address and similar source IPs will help detect any successful reconnaissance before it escalates into a breach.