Severe Risk
IP 175.110.122.163 is a high-risk address operated by WorldStream B.V. in the Netherlands that has generated 507 abuse reports and is actively conducting IoT-targeted exploitation attempts against exposed smart devices and industrial systems, representing a critical threat to any unhardened networked hardware.
Analysis of the available telemetry shows this address was first reported in April 2026 and remained active through May 2026, accumulating a threat score of 10 out of 10 with a 94 percent confidence rating. The IP was detected exclusively through automated honeypot sensors, with 20 separate reports documenting IoT and ICS-targeted attack patterns. The network is AS49981, operated by WorldStream B.V., a Netherlands-based hosting provider. The activity frequency score of 8 out of 10 indicates sustained, repeated engagement rather than a single opportunistic scan, suggesting this address is part of an organized scanning or exploitation campaign against IoT infrastructure.
The dominant threat category, IoT-targeted attacks, focuses on exploiting weak security configurations in connected devices such as cameras, routers, sensors, and industrial control systems. Attackers leverage default credentials, unpatched firmware, and exposed management interfaces to gain persistent access to these devices, often recruiting them into botnets or using them as pivot points into internal networks. The ICS component indicates potential targeting of operational technology environments where compromised devices could disrupt manufacturing, utilities, or critical infrastructure operations. Organizations with inadequately segmented IoT deployments face the highest risk from this activity pattern.
Defensive measures should include immediate blocking of this IP at the network perimeter firewall, implementation of strict access controls on all IoT management interfaces, and network segmentation to isolate smart devices from critical systems. Organizations should audit connected devices for default credentials, ensure firmware is current, and disable unused services such as Telnet or UPnP. Continuous monitoring with tools like fail2ban or equivalent intrusion detection systems can alert defenders to repeated connection attempts from this source.