Maximum Danger
IP 20.65.219.72, registered to Microsoft's AS8075 infrastructure in the United States, is a maximum-threat-level address with a 10/10 risk rating that has generated 167 abuse reports across automated honeypot sensors since October 2025. With 19 hacking-category incidents and multiple reconnaissance activities documented, this IP represents a persistent, high-confidence threat vector that organisations with exposed services should actively block.
The volume and consistency of reporting paint a clear picture of sustained malicious intent. Twenty separate honeypot sensors detected this address repeatedly between October 2025 and May 2026, generating 167 reports with an activity frequency rated 4/10. The dominant threat category was hacking activity at 19 confirmed incidents, supplemented by three port scan detections and two instances where the address exhibited characteristics of an exploited host being weaponised without the operator's knowledge. The IoT-targeted activity noted in one report aligns with the detection of a Zmap user-agent in port scan events—a hallmark of automated, large-scale network reconnaissance tools designed to map internet-facing systems at speed.
Port scanning using tools like Zmap constitutes early-stage attack reconnaissance, mapping open services and potential vulnerabilities before more targeted exploitation attempts. The ET SCAN Suricata signatures triggered repeatedly confirm that this address was actively probing for open ports and weak protocols. When combined with the IoT targeting activity and evidence that the host may itself be compromised and remotely controlled, this IP poses a dual risk: it may be scanning on behalf of threat actors, or it may already be part of a botnet scanning for additional vulnerable devices. Either scenario means exposed services associated with this address face heightened breach risk.
Defensive measures should include immediate ingress blocking of IP 20.65.219.72 at network perimeter firewalls, implementation of fail2ban or similar dynamic blocking tools to auto-drop repeated scan attempts, and restriction of unnecessary exposed services to reduce attack surface. Organizations should also monitor logs for similar scanning signatures from adjacent address ranges, ensure all internet-facing systems are patched current, and consider notifying the hosting provider given the exploited-host classification, which suggests the address may belong to an unwitting victim rather than a deliberate attacker.