Elevated Risk
IP 122.3.195.73 is a high-risk address associated with sustained port scanning and hacking activity, with 244 reported incidents logged by automated honeypot sensors over approximately two months in early 2026. The threat level of 8/10 and activity frequency of 8/10 indicate consistent, deliberate reconnaissance and intrusion attempts originating from the Philippine Long Distance Telephone Company network (AS9299).
Detection data reveals 244 total abuse reports attributed to this single address, with port scanning representing the dominant threat category at 20 recent reports and hacking activity close behind at 19 reports. Honeypot sensors documented CiscoASA port scan probes and Suricata stream anomalies indicating malformed packet transmission, patterns consistent with network reconnaissance and potential vulnerability probing. The Philippines-based IP has been actively reported since April 2026, with the most recent activity logged in May 2026, demonstrating persistent engagement against target infrastructure.
Port scanning operations serve as preliminary reconnaissance, mapping exposed services and identifying entry vectors before any exploitation attempt. The accompanying hacking activity suggests the operator is not merely surveying but actively attempting to leverage discovered weaknesses. The observed malformed packet patterns may indicate attempts to evade detection or probe firewall rule effectiveness. Together, these behaviors represent the early stages of a structured attack campaign against exposed services.
Site operators should immediately block or rate-limit traffic from this IP at the network perimeter firewall and implement strict inbound connection policies. Deploying automated threat-response tools such as fail2ban can neutralize repeated scanning attempts in real time. Intrusion detection systems should be tuned to flag port scan signatures and anomalous packet structures originating from this source. Regular vulnerability scanning and prompt patching of exposed services will reduce the effectiveness of any exploitation attempts.