Severe Risk
IP 175.110.122.153, registered in the Netherlands and operated by WorldStream B.V. under ASN AS49981, presents a critical threat level of 10/10 with a 94% confidence score, driven predominantly by IoT-targeted attack activity detected across automated honeypot sensors over a compressed reporting window from April to May 2026.
The address generated 525 total abuse reports with an activity frequency rated 8/10, indicating sustained, high-volume hostile reconnaissance and exploitation attempts rather than opportunistic or isolated scanning. All 20 most recent reports categorise the observed behaviour as IoT Targeted, signalling a focused campaign against internet-connected devices. The Netherlands-based hosting infrastructure of WorldStream B.V. has been implicated in prior abuse campaigns, though this specific address's activity profile demonstrates deliberate and persistent targeting of smart devices, cameras, routers and other connected hardware reachable from the public internet.
IoT-targeted attacks exploit the notoriously weak security posture of consumer and enterprise connected devices, leveraging default credentials, unpatched firmware and exposed management interfaces to establish persistent footholds. For an organisation with directly addressable IoT devices, a source generating this volume of IoT-focused probes represents a severe compromise risk, potentially preceding ransomware deployment, botnet recruitment or covert data exfiltration through compromised endpoints.
Site operators should immediately block or aggressively rate-limit traffic from this address at the network perimeter, implement network segmentation to isolate IoT devices from critical infrastructure, and audit all connected devices for default credentials and firmware currency. Deploying fail2ban or equivalent dynamic firewall rules on exposed services will further mitigate automated attack surface. Continuous monitoring for IoT-specific intrusion signatures is strongly advised given the sustained nature of this threat.