Extreme Threat
IP 78.153.140.147 is a critical-risk address linked to 819 reported incidents of web application reconnaissance and probing, originating from Hostglobal.plus Ltd infrastructure in the United Kingdom. With a threat level rating of 10 out of 10, this address presents a severe danger to any publicly accessible web service it targets.
Abuse reports logged between August 2025 and May 2026 document sustained malicious activity attributed to this IP, with automated honeypot sensors filing all 20 of the most recent categorizations as web application attacks. The nine-month detection window shows a consistently high activity frequency of 8 out of 10, indicating persistent rather than sporadic engagement. The 78% confidence score reflects the certainty of the automated classification while acknowledging inherent limitations in sensor-based attribution. Hostglobal.plus Ltd operates this address under ASN AS202306, placing the infrastructure within a United Kingdom-based network.
Web application attacks exploit vulnerabilities in internet-facing software, including injection flaws, cross-site scripting, cross-site request forgery, and file inclusion weaknesses documented in the OWASP Top 10. The probing activity detected from 78.153.140.147 appears designed to identify exploitable entry points before launching targeted exploitation. A web application left unpatched or misconfigured faces substantial risk of unauthorized access, data theft, or complete server compromise when subjected to such systematic reconnaissance. The volume of 819 reports over a nine-month period demonstrates automated, continuous scanning typical of infrastructure used for widespread vulnerability scanning rather than isolated opportunistic attempts.
Network operators should immediately block this IP at the firewall level and implement geolocation-based restrictions if United Kingdom origin is not required for legitimate access. Deploying a Web Application Firewall provides critical filtering against the types of probing patterns observed. Keeping all web-facing applications current with security patches eliminates the exact vulnerabilities such reconnaissance aims to discover. Tools like fail2ban can automatically ban repeated offending addresses based on log analysis, while continuous monitoring for the IP address in access logs helps identify any successful reconnaissance or attempted exploitation before damage occurs.