Substantial Risk
IP 207.90.244.19 is a high-risk address linked to sustained hacking activity, with a threat level of 8 out of 10 and a 98% confidence rating based on 425 total abuse reports spanning August 2025 through June 2026. The volume and consistency of these reports indicate persistent, deliberate hostile intent rather than isolated scanning. This IP presents a concrete danger to any exposed service accepting connections from US-based sources.
Automated honeypot sensors and community reports have documented this address over approximately ten months, with the most recent 20 reports categorizing the activity as general hacking attempts. The network originates from AS174 (Cogent-174), one of the largest internet service providers operating in the United States. The activity frequency score of 8 out of 10 demonstrates that connection attempts are not sporadic but represent a sustained campaign, likely automated, against target systems worldwide.
Hacking activity in this context encompasses various intrusion techniques including vulnerability exploitation, systematic probing, and unauthorized access attempts. The detected "attack connection" pattern suggests the IP is establishing connections to target services with the intent to exploit weaknesses, conduct credential-based attacks, or enumerate system configurations. Any exposed SSH, remote desktop, web application, or administrative interface is a potential target. The US origin and major ASN suggest this traffic may transit through or originate from compromised infrastructure, proxy services, or residential networks being abused for malicious purposes.
Network operators should immediately block or rate-limit this address at the perimeter using standard defensive tools such as fail2ban, firewall rules, or web application firewalls. Exposed services should enforce strong password policies, key-based authentication where possible, and implement account lockout thresholds to mitigate brute-force attempts. All systems should be kept current with security patches, and intrusion detection systems should be configured to alert on correlated connection attempts from this source. Regular monitoring of access logs for this IP address will help identify any successful reconnaissance or authentication testing.