Elevated Risk
IP 89.248.167.131, registered in the Netherlands under ASN AS202425 (IP Volume inc), presents a critical threat with a maximum threat-level score of 10 out of 10 and a confidence rating of 91 percent, placing it among the highest-risk addresses currently tracked by automated honeypot sensors and community reporting networks. The IP has accumulated 171 total abuse reports across a six-month operational window spanning January through June 2026, with an activity frequency rated 8 out of 10, indicating sustained and aggressive malicious behaviour throughout this period.
The volume and consistency of reports against 89.248.167.131 are particularly concerning: 20 separate automated honeypot sensors detected the address engaging in hacking activity, exploited-host behaviour, and IoT-targeted operations. Of the reported threat categories, Hacking dominates with 16 instances, followed by Exploited Host with 3 cases and IoT Targeted activity with 1 report. The abstract attack-pattern indicators associated with this IP include attack connections, IoT and ICS targeting, malware and exploit activity, and Redis-specific attack vectors. The combination of multiple concurrent threat vectors and the volume of distinct detection sources strongly suggests this address is not merely a transient scanner but an actively maintained attack platform operating continuously over an extended timeframe.
The dominant Hacking classification indicates the IP is conducting intrusion attempts, vulnerability exploitation, and unauthorized-access probing against exposed services, while the Exploited Host designation raises the possibility that infrastructure associated with this address may itself be compromised and repurposed as an attack launchpad. The presence of IoT and ICS targeting patterns, coupled with Redis-specific attack activity, suggests the operator behind 89.248.167.131 is pursuing a diverse threat portfolio targeting smart devices, industrial-control systems, and poorly secured database services. This multi-vector approach amplifies real-world risk, as successful compromise of any single exposed service can cascade into broader network infiltration, data exfiltration, or lateral movement within victim environments.