Critical Threat
IP address 175.110.122.156 is a critical-risk address assessed at 10/10 threat level with a 94% confidence score, predominantly linked to IoT-targeted attack campaigns against smart devices, cameras, routers and other connected infrastructure. This Netherlands-based host accumulated 508 abuse reports across approximately two months of active scanning activity between April and May 2026, with an activity frequency rated 8/10 indicating sustained, repeated offensive operations rather than isolated probes.
The volume and consistency of reports against 175.110.122.156 point to systematic exploitation attempts rather than opportunistic scanning. All 508 reports originated from automated honeypot sensors designed to replicate vulnerable IoT and ICS environments, suggesting the attacking host is actively hunting for misconfigured or unpatched connected devices across the internet. The address routes through AS49981 operated by WorldStream B.V., a Dutch hosting provider, which means the malicious traffic originates from infrastructure within the Netherlands rather than compromised end-user equipment. The concentration of identical IoT-targeted activity across twenty separate detection sensors over a compressed two-month window demonstrates methodical, automated reconnaissance and exploitation preparation.
IoT-targeted attacks represent a concrete and growing threat because internet-connected devices frequently ship with weak default credentials, unpatched firmware and exposed management interfaces that attackers can compromise at scale. Once a vulnerable device is compromised, it can be weaponised for botnet recruitment, data exfiltration, lateral movement into internal networks or participation in distributed denial-of-service campaigns. The 508 reports logged against 175.110.122.156 indicate this host is actively working through lists of IoT endpoints, probing for Telnet, SSH, HTTP and other management ports commonly left open on smart devices. The real-world risk is immediate: any organisation with poorly secured IoT deployments directly in the attacker's path faces a high probability of compromise if additional hardening measures are not applied.
Organisations should immediately block 175.110.122.156 at the network edge or firewall level given its confirmed malicious activity profile. Network segmentation isolating IoT devices from critical business systems is essential to limit blast radius if a device is successfully targeted. Device administrators should audit all connected hardware, update firmware to current versions and replace any default credentials with strong, unique passwords. Deploying intrusion detection systems or monitoring tools such as fail2ban can help identify and auto-block repeated connection attempts from high-frequency sources like this address.