Severe Risk
IP 187.188.118.10 is a critical-risk address originating from Mexico that has been classified as an exploited host, with automated honeypot sensors recording 225 abuse reports between October 2025 and May 2026. The IP, operated by TOTAL PLAY TELECOMUNICACIONES SA DE CV under ASN AS22884, presents a maximum threat level of 10/10, driven primarily by confirmed exploitation activity targeting vulnerable server message block infrastructure.
The threat assessment draws from 20 distinct automated honeypot sensors that collectively generated 225 reports over approximately seven months, with the dominant classification being exploited host (20 reports) alongside general hacking activity (5 reports). The confidence score stands at 61%, reflecting moderate certainty in the categorization. Network detection signatures specifically flagged potentially unsafe SMBv1 protocol usage consistent with malware or exploit delivery, indicating active engagement in propagating known attack vectors. Despite an activity frequency rating of 0/10, the severity of individual detected events — particularly SMBv1 exploitation patterns — elevates the overall risk profile to critical, suggesting this address operates as a compromised platform launching outbound attacks without the owner's knowledge.
An exploited host classification indicates that IP 187.188.118.10 is almost certainly a victim system that has been co-opted by threat actors to conduct malicious activity, meaning the operator may be unaware their infrastructure is participating in attacks. The SMBv1 exploitation activity aligns with historical patterns used to deliver ransomware and establish persistent remote access, posing a direct risk to any exposed SMB services reachable from this address. The real-world danger lies not only in the outbound malicious traffic originating from this host but also in the likelihood that the compromised system harbors additional persistent threats that could spread laterally or exfiltrate data.
Site operators should immediately block IP 187.188.118.10 at the network perimeter and implement firewall rules denying inbound connections from this address. Exposed SMB services should be audited and, where possible, SMBv1 should be disabled entirely to eliminate the exploitation vector. Deploying tools such as fail2ban or equivalent intrusion prevention mechanisms can automate the blocking of repeated probe patterns. Operators are encouraged to consider notifying the hosting provider, TOTAL PLAY TELECOMUNICACIONES SA DE CV, to facilitate remediation of the compromised system and prevent its continued use as an attack platform.