Extreme Threat
IP 175.110.122.162 is a high-risk address operating from Netherlands-based hosting infrastructure AS49981 (WorldStream B.V.), assessed at a 10/10 threat level with 94% confidence following 509 abuse reports logged between April and May 2026. The dominant threat profile is IoT-targeted reconnaissance and exploitation activity, consistent with scanning behavior aimed at vulnerable connected devices, cameras, routers and industrial control systems. With an activity frequency rated 8/10, this IP has demonstrated persistent, repeated engagement against honeypot sensors over a concentrated timeframe, placing it firmly in the category of actively hostile infrastructure that any exposed service should treat as a direct threat.
All 20 categorized reports — sourced entirely from automated honeypot sensors — flag IoT and ICS targeting, indicating a narrow and deliberate focus rather than opportunistic noise. The volume of total reports (509) relative to the recent narrow category window suggests this IP may have cycled through multiple threat profiles or contributed to a broader scanning campaign, with the current IoT focus representing its most recent confirmed behavior. The Netherlands hosting environment provides the network layer; WorldStream B.V.'s ASN is known within the community as carrying mixed-use traffic, which this IP's behavior reinforces. The April–May 2026 reporting window is contained but aggressive, and the 94% confidence score gives strong analytical reliability to the classification.
IoT-targeted attacks exploit weak security postures in smart devices, routers and industrial equipment — factory-default credentials, unpatched firmware and exposed management interfaces are the primary entry vectors. An IP conducting such reconnaissance at this volume is almost certainly building a target list for follow-on compromise, botnet recruitment or secondary exploitation. For any organization running exposed IoT infrastructure, this activity represents a concrete pre-attack threat: the gap between scanning and successful exploitation can be very short, and devices compromised through such campaigns are routinely weaponized for DDoS, data exfiltration or lateral movement into wider networks.