Severe Risk
IP 64.62.197.47, routed through Hurricane Electric's network (AS6939) in the United States, presents a maximum threat level of 10/10 based on 196 abuse reports submitted by automated honeypot sensors across a nine-month observation window from August 2025 through April 2026. The confidence score of 71% reflects substantial but not unanimous agreement among detection systems regarding the nature and intent of this address's activity. Despite an activity frequency reading of 0/10 indicating a recent lull in detection, the accumulated report volume and threat classification make this IP a high-priority candidate for blocking at network perimeters.
The reported threat categories reveal a multi-vector risk profile dominated by general hacking activity (18 reports), followed by IoT-targeted attack patterns (2 reports) and a single classification as an exploited host (1 report). The "exploited host" designation is particularly significant, as it suggests this IP address belongs to a system that has been compromised and is now being weaponized by threat actors to conduct attacks against other targets, effectively turning the innocent owner's infrastructure into an attack platform. Detection sources specifically noted patterns consistent with malware or exploit activity and attack connections specifically targeting IoT and industrial control systems, suggesting this compromised host has been enrolled in a botnet or similar attack infrastructure.
The combination of high report volume, maximum threat classification, and the exploited host designation means this address poses a concrete risk to any exposed service. An exploited host operating from a major US backbone provider can generate significant attack volume while benefiting from the reputational shield of a legitimate network operator, making detection and attribution more difficult for defenders. Organizations with publicly accessible services, particularly those managing IoT deployments or industrial systems, face elevated risk from any continued use of this address in their logs, as it indicates either active compromise of the reporting system or ongoing scanning and exploitation attempts originating from the compromised infrastructure.