Critical Alert
IP 91.244.254.217 is a critical-risk address assigned to SkyNetwork Ltd. in Russia that has been identified as an exploited host based on 185 total abuse reports from automated honeypot sensors between August and October 2025. With a threat level scored at 10 out of 10 and 20 confirmed exploit-related incidents in recent reports, this IP presents a severe and immediate danger to any exposed services. The detection spans a concentrated three-month window, indicating sustained malicious use of a compromised infrastructure rather than isolated probing activity.
Analysis of the 185 aggregate reports reveals consistent detection by 20 separate automated honeypot sensors, pointing to coordinated observation of this address across multiple monitoring points. The network is registered to SkyNetwork Ltd. under ASN AS31566, routing through Russian telecommunications infrastructure. While the activity frequency metric appears low at 0 out of 10, this likely reflects the nature of exploit delivery mechanisms rather than benign intent, as the dominant threat classification centers on exploitation activity originating from a host that appears to be under unauthorized control. The 65% confidence score suggests some uncertainty in full attribution, but the volume and consistency of reports substantiate a high-confidence threat assessment overall.
An exploited host classification indicates that the machine operating under IP 91.244.254.217 has been compromised by threat actors and is now being weaponized as an attack platform, often without the knowledge of its legitimate owner. This scenario transforms an otherwise unsuspecting endpoint into a dangerous asset capable of launching further attacks, distributing malware payloads, or serving as a command-and-control relay. For network defenders, an exploited host poses a particularly insidious risk because its traffic may exhibit patterns that differ significantly from known malicious IPs, potentially evading basic detection mechanisms that rely on reputation scoring alone. The presence of exploit-related activity suggests that this host may be actively scanning or attempting to compromise additional vulnerable systems within range.