Critical Alert
IP address 175.110.122.161 is a critical-risk Dutch address operated by WorldStream B.V. that has generated 495 abuse reports within a two-month window, with honeypot sensors flagging it exclusively for IoT-targeted attack campaigns against connected devices and industrial control systems. The IP's 10/10 threat level and 94% confidence rating reflect sustained, high-volume reconnaissance and exploitation activity originating from AS49981, making it a confirmed danger to any exposed IoT infrastructure on the internet.
Automated honeypot sensors filed all 495 reports against 175.110.122.161 between April and May 2026, with an activity frequency rated 8/10 — indicating near-continuous engagement with vulnerable targets rather than sporadic opportunistic scanning. The Dutch network operator WorldStream B.V. (ASN AS49981) hosts this address, and the concentration of reports exclusively targeting IoT and ICS environments suggests a deliberate, purpose-built campaign rather than general internet noise. With a confidence score of 94%, the attribution to malicious IoT probing is highly reliable across all detection sources.
IoT-targeted attacks exploit weak security controls in smart cameras, routers, sensors, and industrial equipment — often leveraging default credentials, unpatched firmware, and exposed management interfaces to gain persistent access or recruit devices into botnets. The specific focus on IoT/ICS systems means this IP is systematically probing for devices that frequently lack enterprise-grade security, using their compromise to access sensitive data, disrupt operations, or pivot into broader network infrastructure. The sustained frequency and report volume confirm an active, ongoing threat rather than a single probing event.
Site operators with exposed IoT deployments should immediately block or aggressively rate-limit traffic from 175.110.122.161 at the network perimeter and consider implementing automatic blocking mechanisms such as fail2ban to deter repeated attempts. Network segmentation isolating IoT devices from critical systems is essential, as is auditing all connected devices for default credentials, disabling unused services including UPnP, and applying firmware updates promptly. Continuous monitoring for IoT-specific scanning signatures will help detect and neutralize future engagement from this or related hostile addresses.