Critical Alert
IP 175.110.122.152 is a critical-risk address linked to high-volume IoT-targeted reconnaissance and exploitation attempts, with 507 abuse reports submitted to threat-sharing communities over approximately two months in early 2026. Originating from WorldStream B.V. (ASN AS49981), a Netherlands-based hosting provider, this IP exhibits an activity frequency rating of 8/10 and carries a confidence score of 94 percent, indicating that automated honeypot sensors have consistently identified hostile intent with near-certain attribution. The sustained volume and concentrated detection window make this one of the more aggressively profiled IoT-focused threats in recent community reporting cycles.
The 507 reports logged against 175.110.122.152 span first detections in April 2026 through late May 2026, with all 20 recent reports citing IoT Targeted activity as the dominant threat category. Twenty distinct automated honeypot sensors flagged the address during this period, suggesting the scanning behavior is broad, automated, and ongoing rather than a isolated probe. The IP's placement within WorldStream B.V.'s network infrastructure is notable, as this ASN has appeared in prior threat intelligence for hosting addresses associated with scanning and exploitation toolkits targeting internet-connected devices.
IoT-targeted attacks exploit the chronically weak security posture of smart devices, cameras, routers, and industrial control systems that lack robust patch management, use default credentials, or expose management interfaces to the public internet. An address exhibiting this behavior at high frequency is typically engaged in mass scanning for vulnerable devices it can co-opt into botnets, weaponize for distributed denial-of-service campaigns, or pivot through for deeper network intrusion. The real-world risk to an exposed IoT device is complete compromise: data exfiltration, surveillance hijacking, or enrollment in attacker-controlled infrastructure. For organizations with unsegmented IoT deployments, a single vulnerable device responding to such scanning can become the entry point for lateral movement.
Site operators should immediately block or rate-limit connections from 175.110.122.152 at the network edge and monitor inbound traffic patterns for similar scanning signatures from adjacent address space. Network segmentation isolating IoT devices from critical systems is essential to limit blast radius. Device firmware should be verified current, default credentials replaced with strong unique passphrases, and unused services such as UPnP disabled. Deploying defensive tools such as fail2ban or equivalent log-analysis automation can dynamically ban repeated probe attempts from this and related addresses.