Maximum Danger
IP 185.55.240.152, allocated to Layer7 Networks GmbH in Germany under ASN AS199912, presents a critical threat level of 10/10 based on 458 abuse reports generated through 20 automated honeypot sensors between February and March 2026. The address is classified as an exploited host, indicating a compromised server weaponized for malicious activity without the owner's knowledge.
The detection data reveals sustained hostile behavior, with automated sensors across the network community documenting repeated exploitation attempts targeting known vulnerabilities. Suricata signatures identified attempts against SolarWinds Orion API (CVE-2020-10148), Sar2HTML plotting tool for Linux servers, and DrayTek products susceptible to pre-authentication remote code execution (CVE-2020-8515). Additionally, the honeypots logged IoT-targeted connection attempts and anomalous HTTP header repetition patterns. The 458 reports spanning 20 distinct sensor sources demonstrate persistent, systematic scanning and exploitation activity rather than isolated probes.
The "exploited host" classification means this IP represents a compromised infrastructure element now serving as an attack platform. The owner of this German-hosted system likely remains unaware their asset participates in global attack campaigns. The diverse exploit signatures suggest automated toolkits deploying multiple vulnerability modules against internet-facing services. Organizations with SolarWinds, DrayTek, or similar enterprise infrastructure face direct intrusion risk if exposed to this source. Compromised hosting IPs also frequently rotate attack vectors, meaning today's exploit signatures may differ from tomorrow's.
Site operators should immediately block 185.55.240.152 at network perimeter devices and implement fail2ban or equivalent rule sets matching the observed attack patterns. Ensure all SolarWinds, DrayTek, and web-facing applications maintain current security patches, particularly for the identified CVEs. If this IP appears in inbound connection logs, treat it as a confirmed compromise attempt and audit affected systems for indicators of prior access. Hosting providers and network operators receiving abuse notifications should investigate whether customer VMs or bare-metal instances have been breached and require remediation.