Critical Threat
IP 141.98.10.108 is a maximum-threat-level address that has accumulated 172 reported hacking incidents detected by automated honeypot sensors, originating from Lithuania and operated by UAB Host Baltic on ASN AS209605. With a threat rating of 10 out of 10 and a 79% confidence score, this IP represents a significant and confirmed danger to any exposed network service during its active window between March and April 2026.
Analysis of the available telemetry shows this address generated substantial abuse reports over a compressed two-month period, with all 20 recent threat-category classifications pointing to hacking activity. The detection network attributed every report to automated honeypot sensors, indicating systematic and repeated intrusion attempts rather than opportunistic scanning. Although the activity frequency metric rates as low, the volume of distinct reports combined with the maximum threat classification confirms this IP has demonstrated sustained hostile intent that network defenders should treat with high urgency.
The dominant hacking activity associated with this address encompasses various intrusion techniques including vulnerability exploitation attempts and unauthorized access probes against exposed services. In concrete terms, an unpatched or misconfigured service facing this IP could be targeted for credential compromise, command injection, or exploitation of known software weaknesses. The systematic nature of the detected attacks suggests the IP may be part of an automated campaign rather than isolated manual probing, amplifying the risk to any vulnerable surface.
Organizations with internet-facing infrastructure should block 141.98.10.108 at the network perimeter and ensure blocking rules propagate to edge firewall devices. Implementing fail2ban or equivalent dynamic denial-of-service tools can automatically update blocklists based on repeated authentication failures from this source. All exposed services should be audited for current patches and hardened authentication controls, particularly on remote access protocols. Continuous monitoring for this IP address in inbound connection logs is strongly recommended to detect any resumption of hostile activity.