Maximum Danger
IP 78.153.140.149 is a critical-risk address generating 724 abuse reports, with a maximum threat score of 10/10 and an eight-month sustained campaign of web application probing detected across multiple automated honeypot sensors. The dominant threat category is Web App Attack, representing 100% of recent reportable activity.
The address, routed through AS202306 (operated by Hostglobal.plus Ltd) and geolocated to Great Britain, was first reported in August 2025 and remained active through May 2026. The 78% confidence score reflects substantial corroboration across the reporting sensor network, indicating persistent and repeated automated scanning behavior rather than isolated opportunistic probes. Activity frequency scored 8/10 demonstrates continuous, high-volume engagement with target web services throughout the observation window.
Web application attacks target vulnerabilities in internet-facing software, including injection flaws, authentication weaknesses, and configuration missteps that could expose backend systems. The sustained, probe-focused pattern suggests the operator is systematically mapping potential entry points across exposed web properties rather than exploiting a single known vulnerability. This reconnaissance methodology poses a concrete risk to any unpatched or misconfigured web application accessible from this address, as successful exploitation could lead to data compromise, service disruption, or further network penetration.
Site operators should immediately block this IP at the network perimeter or via firewall rules, particularly if no legitimate traffic is expected from this address. Deploying a Web Application Firewall will help detect and filter malicious request patterns associated with this scanning activity. Keeping all web applications updated and conducting regular security assessments to eliminate OWASP Top 10 class vulnerabilities significantly reduces exposure. Automated tools such as fail2ban can proactively ban IPs demonstrating sustained probing behavior, while monitoring logs for the identified patterns enables rapid incident response if exploitation attempts escalate.