Critical Threat
IP 175.110.122.159, allocated to WorldStream B.V. in the Netherlands via AS49981, presents a critical threat with a 10/10 threat level and a 94% confidence score, driven by 530 abuse reports over approximately two months of active targeting of IoT and ICS infrastructure.
Automated honeypot sensors detected this address conducting hostile reconnaissance and exploitation attempts against internet-connected devices, with all 20 of the most recent reports categorizing the activity as IoT-targeted attacks. The IP demonstrated sustained engagement with an activity frequency rating of 8/10, first appearing in community reports in April 2026 and remaining active through May 2026. The Netherlands-based allocation through a commercial hosting provider suggests the infrastructure may be rented or compromised, common tactics for attackers seeking geographic diversity to evade regional blocks.
IoT-targeted attacks exploit the notoriously weak security posture of smart devices, cameras, routers, and industrial control systems that often ship with default credentials, unpatched firmware, and exposed management interfaces. An attacker operating from this address poses a concrete risk to any organization running exposed IoT or ICS deployments, as successful exploitation can grant persistent access to internal networks, enable lateral movement, or weaponize devices into botnets for subsequent DDoS or cryptojacking campaigns.
Site operators should immediately block or rate-limit traffic from this address at the network edge, ensure all IoT devices run current firmware and use non-default credentials, and disable Universal Plug and Play on routers and network devices. Implementing network segmentation to isolate IoT infrastructure from critical systems limits the blast radius of any successful compromise. Deploying defensive tools such as fail2ban or equivalent brute-force mitigation can further reduce exposure to credential-based attacks originating from suspicious IPs.