Critical Alert
IP 146.70.124.165 is a critical-risk address operated by M247 Europe SRL in Romania that has been flagged in 749 abuse reports as an active source of hacking activity targeting exposed services.
The IP has accumulated 749 reports with a perfect 10/10 threat level rating, though its activity frequency score is listed at 0/10, suggesting the cumulative abuse volume is significant while recent real-time connection attempts may have tapered. All 20 analyzed reports originated from automated honeypot sensors, lending technical credibility to the findings, with a confidence score of 76% placing substantial weight on the intelligence. The activity was first documented in November 2025 and continued through December 2025, indicating at least two months of sustained hostile reconnaissance or intrusion attempts. M247 Europe SRL, operating under ASN AS9009, is a European infrastructure provider that has historically hosted both legitimate and malicious traffic due to its broad service offerings.
The dominant reported threat category is hacking, encompassing various intrusion attempts, vulnerability exploitation and unauthorized access probes against exposed services. While specific attack patterns have been sanitized from this briefing, honeypot detections indicate the address has been actively scanning for and probing weaknesses in target systems. The volume of 749 reports, while spread across a two-month window, represents a sustained threat that site operators with exposed services should treat as malicious until proven otherwise. The low activity frequency score may indicate declining engagement with current defensive perimeters, though the underlying intent remains unambiguously hostile.
Administrators managing publicly accessible services should immediately block this IP at the firewall or network edge based on its critical threat classification. Implementing automated blocking tools such as fail2ban can dynamically respond to the observed probing patterns detected by honeypot sensors. All exposed services should be audited for unnecessary exposure, and access controls should be hardened with strong authentication requirements. Continuous monitoring for connection attempts from this address will help identify any renewed scanning activity.