Significant Threat
IP 18.116.101.220 is a high-risk address operating from Amazon Web Services infrastructure (AS16509, AMAZON-02) that has generated 3,470 abuse reports between February and August 2026, indicating sustained malicious activity dominated by hacking intrusion attempts detected across 20 automated honeypot sensors with a threat level rating of 8 out of 10.
The report volume for this United States-based IP address is substantial, with an activity frequency rated at 8 out of 10, suggesting persistent scanning and exploitation behaviour over a seven-month window. Analysis of the most recent 22 reports categorises the threat profile as primarily hacking activity (19 reports), complemented by two exploited host indicators and one IoT-targeted report. The detected attack patterns include general attack connections, malware and exploit activity, and specifically a Suricata alert flagging application-layer protocol detection occurring in only one communication direction. These patterns align with automated exploitation toolkits and reconnaissance probes commonly associated with credential guessing, vulnerability scanning, and post-compromise payload delivery attempts.
Hacking activity as the dominant threat category encompasses unauthorised access attempts, vulnerability exploitation, and intrusion probes that target exposed services running on internet-facing systems. The presence of malware and exploit-related patterns suggests this address may be utilised to deliver or execute malicious payloads. The exploited host signals raise the possibility that the IP address itself, or systems operating within this AWS allocation, may have been compromised and are being weaponised without the operator's knowledge to conduct secondary attacks. IoT targeting activity, though minimal in recent reports, indicates potential interest in smart devices, cameras, or industrial control systems with weak security configurations.
Site operators should block or rate-limit connections from 18.116.101.220 at the network perimeter, implement strong authentication mechanisms on all exposed services, and deploy intrusion detection systems to monitor for the observed attack patterns. Keeping systems patched and following security best practices significantly reduces vulnerability to the exploitation techniques this address employs. Deploying defensive tools such as fail2ban can automate blocking responses to repeated connection attempts characteristic of brute-force activity. Network segmentation of IoT devices and disabling unnecessary protocols limits the attack surface available to this threat actor.