Severe Risk
IP 141.98.10.99 is a Lithuanian address linked to critical hacking activity with a maximum threat rating of 10/10 and 231 independent abuse reports filed against it through automated honeypot sensors between March and April 2026. The IP is associated with AS209605, operated by UAB Host Baltic, and carries a 74% confidence score for malicious intrusion attempts and exploitation of vulnerable services.
The report volume of 231 incidents over a two-month window indicates sustained, persistent offending rather than opportunistic scanning, which distinguishes this address from typical automated noise. All reported incidents originate from automated honeypot sensors, confirming the activity represents deliberate scanning and attack tooling rather than misconfiguration or benign traffic. The geographic origin in Lithuania and the AS209605 network assignment provide context for attribution, though the address may be operating as part of a larger compromised or bulletproof hosting infrastructure. The activity frequency metric of 0/10 suggests that while the abuse history is extensive, the current attack cadence has either decreased or been successfully mitigated at sensor level.
The dominant threat category of hacking encompasses automated vulnerability probing, exploitation attempts against unpatched services, and intrusion vectors designed to gain unauthorized system access. A threat score of 10/10 indicates the activity has demonstrated clear malicious intent with high potential impact, capable of compromising exposed services ranging from web servers to administrative interfaces if vulnerabilities are present. The real-world risk includes data breach, host compromise, lateral movement within networks, or recruitment into botnets.
Network defenders should block this address at the perimeter firewall level, implement strict rate-limiting on authentication and remote access services, and ensure all internet-facing systems are current with security patches. Deploying fail2ban or similar intrusion prevention tooling on SSH and web services can automatically block repeated attack patterns. Continuous monitoring of connection attempts from this and similar high-threat addresses will enable rapid response to any renewed activity.