Extreme Threat
IP 175.110.122.160 is a critical-risk address operating from WorldStream B.V. infrastructure in the Netherlands, with 518 abuse reports logged over approximately two months and a threat level of 10/10, indicating it is actively engaged in IoT-targeted attacks against smart devices, cameras, routers, and connected equipment worldwide.
Analysis of the available data shows this address generated 518 total reports from 20 automated honeypot sensors between April and May 2026, producing an activity frequency rating of 8/10 and a confidence score of 94 percent. Every reported incident during this period was classified under the IoT Targeted category, making the threat profile remarkably focused. The Netherlands-based autonomous system AS49981, operated by WorldStream B.V., routes this traffic, placing the IP within a commercial hosting environment commonly associated with both legitimate and malicious server infrastructure. The concentration of reports across multiple honeypot sensors over a compressed timeframe demonstrates sustained, deliberate scanning behaviour rather than opportunistic or accidental traffic.
IoT-targeted attacks represent a significant threat to any exposed smart devices, network cameras, residential routers, and industrial control systems that lack robust security hardening. Attackers automating scans of this nature are typically harvesting devices with default credentials, unpatched firmware, or exposed management interfaces to recruit them into botnets or gain unauthorized access to internal networks. The real-world risk extends beyond the compromised device itself; poorly secured IoT endpoints frequently serve as entry points for lateral movement into corporate or home networks, enabling data exfiltration, further exploitation, or use in distributed denial-of-service campaigns.
Network operators should immediately block or rate-limit traffic originating from 175.110.122.160 at the firewall or network edge, implement strict ingress filtering, and monitor logs for any attempted connections matching this source. Organizations with exposed IoT infrastructure should verify that all devices run current firmware, default credentials have been replaced with strong unique passwords, UPnP is disabled on routers, and IoT segments are isolated from critical network zones using VLANs or dedicated firewall policies. Deploying intrusion detection systems and tools such as fail2ban can further reduce exposure to automated scanning activity of this kind.