Elevated Risk
IP 143.198.238.87 is a high-risk DigitalOcean-hosted address that has generated 6,947 abuse reports through automated honeypot sensors since September 2025, indicating sustained and prolific malicious activity originating from US cloud infrastructure.
The IP has been reported across 20 separate honeypot sensors with an activity frequency rating of 8 out of 10, placing it among the most actively detected threat sources in recent telemetry. The report volume of nearly 7,000 incidents over approximately nine months translates to roughly 25 hostile connection attempts per day — a rate consistent with automated scanning or brute-force operations. The dominant threat category is general hacking activity, supported by secondary IoT-targeted probes and isolated email spam reports. Despite the US country attribution and DigitalOcean's legitimate cloud-infrastructure ASN (AS14061), the IP exhibits clear patterns of compromise or abuse, as confirmed by the 85% confidence score. The IoT/ICS targeting pattern detected suggests the actor behind this IP is systematically searching for vulnerable connected devices and industrial control systems.
The concentration of hacking-related incidents indicates automated exploitation attempts against exposed services, potentially targeting SSH, Telnet, or web-facing applications commonly found on IoT devices and servers. IoT-targeted activity poses a particular risk to organizations with inadequately secured smart devices, cameras, or networked sensors, as these systems often ship with default credentials and minimal patching regimes. Email spam originating from this IP compounds its malicious reputation and may indicate the host has been enrolled in a botnet or relay network. The high report volume and sustained activity window suggest this is not opportunistic probing but persistent hostile infrastructure.
Site operators should implement automated blocking mechanisms such as fail2ban to ban IPs after repeated failed authentication attempts, enforce strong and unique credentials across all exposed services, segment IoT devices onto isolated network zones, and monitor for the specific scanning patterns associated with this IP to identify potential intrusion attempts early.