Critical Alert
IP 85.172.170.162 is a critical-risk address originating from Russian telecommunications infrastructure that has been identified as a compromised system actively participating in malicious network activity, with 162 abuse reports logged between August 2025 and May 2026 and automated honeypot sensors consistently flagging SMBv1 exploitation patterns associated with malware distribution.
Community and automated honeypot sources submitted 162 reports against this address, with 20 distinct sensors detecting malicious behaviour over approximately a nine-month observation window. The dominant classification across recent reports is "Exploited Host," accounting for the majority of detections, indicating that the IP belongs to a victimized system being weaponized by threat actors without the legitimate operator's knowledge. Suricata intrusion-detection signatures specifically flagged potentially unsafe SMBv1 protocol usage, a known vector for lateral movement and malware propagation. The IP routes through Rostelecom's AS33934 network, a major Russian ISP, and the consistent report volume across automated sensors suggests persistent rather than opportunistic malicious operation despite the relatively low activity frequency rating of two out of ten.
An exploited host represents a particularly insidious threat category because the compromised machine often belongs to an innocent organization or end user whose network resources are being leveraged for further attacks. SMBv1 protocol activity is a well-documented indicator of ransomware and worm-style propagation attempts, as the legacy protocol contains known vulnerabilities that permit remote code execution. When a system is confirmed as an exploited host, it typically means the machine is simultaneously a target of compromise and an active platform for launching subsequent attacks against other victims, compounding the overall risk landscape. The 65% confidence score reflects that while the malicious classification is strongly supported by sensor data, definitive attribution of the underlying compromise remains inconclusive.
Site operators should block IP 85.172.170.162 at the network perimeter as an immediate containment measure, given the confirmed malicious classification and sustained abuse report volume. Implementing SMBv1 protocol restrictions across internal assets is strongly advised, as this eliminates the primary attack vector detected in the honeypot telemetry. Deploying fail2ban or equivalent dynamic blocklist tools to automatically quarantine sources exhibiting brute-force or exploit patterns provides layered defence against similar addresses. Organizations should also consider notifying the upstream provider, Rostelecom, to alert them that one of their assigned addresses is functioning as an exploited host within their infrastructure.