Critical Threat
IP 93.170.91.91 is a high-risk address originating from Ukraine that has been classified as an exploited host, indicating it is a compromised system being weaponised for malicious activity without the knowledge of its operator. With a threat level of 10 out of 10 and 181 abuse reports in September 2025 alone, this IP represents a significant and immediate danger to any exposed network service. Automated honeypot sensors detected the hostile activity, confirming that the address is actively participating in attack operations against internet-facing systems. Despite a 60% confidence score, the severity of the threat classification demands that security teams treat this IP as hostile and implement defensive measures without delay.
Security telemetry shows 181 total reports attributed to this address, with 20 of the most recent reports specifically categorising the host as exploited. The malicious activity detected includes malware and exploit operations consistent with a system that has been taken over by threat actors and repurposed as an attack platform. The IP is registered to AS57197 under individual operator Shaporenko Yuri Nikolaevich in Ukraine, and all reported activity occurred within September 2025. The fact that automated honeypot sensors generated all 20 recent reports indicates that this address is running systematic scanning or exploit attempts rather than isolated probing, making it a persistent rather than transient threat.
An exploited host presents concrete risks because the compromised machine can be used to launch distributed attacks, distribute malware, conduct reconnaissance against other targets, or serve as a pivot point to obscure the true origin of malicious traffic. Because the legitimate operator has no awareness of the compromise, the attacking infrastructure appears to be a valid endpoint, which can help it evade basic reputation filters. The absence of activity frequency data suggests that either the scanning is intermittent or the reports capture discrete campaigns rather than continuous traffic, but the volume of reports confirms sustained malicious intent over the reporting period.
Organisations should immediately block IP 93.170.91.91 at the network perimeter and monitor logs for any related connection attempts. Deploying tools such as fail2ban or equivalent rate-limiting mechanisms can help neutralise automated scanning from this and similar addresses. Given that the host appears to be a compromised consumer or business system rather than a known bulletproof hosting provider, considering a notification to the upstream ISP or network operator may help disrupt the active threat. Regularly updating blocklists with reported exploited hosts and enforcing strong authentication on all exposed services will further reduce the attack surface that this IP and others like it attempt to exploit.