Significant Threat
IP 89.42.231.182, allocated to Amarutu Technology Ltd in the Netherlands under ASN AS206264, presents a high-risk threat profile with a threat level of 8/10, driven by automated honeypot detection of persistent hacking activity and evidence that the address may operate as an exploited host being weaponized without its operator's knowledge.
Security sensors across the network reported this address a total of 603 times, with the dominant threat category being Hacking at 17 confirmed incidents, complemented by 3 Exploited Host detections and a single Email Spam report. All activity was identified through 20 distinct automated honeypot sensors between February and March 2026. The Suricata intrusion-detection signatures raised during these encounters indicate the IP engaged in protocol-only communication attempts, malware and exploit activity, and SMTP-based abuse patterns, with some alerts specifically noting SMTP spam and protocol mismatches across both communication directions.
The high volume of hacking activity combined with Exploited Host classifications suggests that IP 89.42.231.182 may serve as a compromised platform conducting automated intrusion attempts and mass-email operations on behalf of threat actors who have gained unauthorized control. Such addresses pose a concrete risk to any publicly accessible service, as they routinely scan for vulnerabilities, attempt credential exploitation, and distribute malicious content through multiple attack vectors simultaneously.
Network operators and security administrators should block IP 89.42.231.182 at the firewall or edge-device level and implement rate-limiting on exposed services to mitigate sustained brute-force or scanning activity. Enabling automated blocking mechanisms such as fail2ban on SSH and web-facing services significantly reduces exposure to the intrusion patterns observed. Email infrastructure should enforce strict SPF, DKIM, and DMARC validation, and any legitimate outbound mail from this address range should be investigated for potential compromise. Providers controlling this IP space are encouraged to review the hosting account associated with AS206264 for signs of compromise or abuse.