Significant Threat
IP 158.173.22.20 is a high-risk address associated with sustained hacking activity, with automated honeypot sensors logging 583 reports and a threat level of 8 out of 10.
The IP originates from the United States on the AS212238 autonomous system operated by Datacamp Limited. All reported activity occurred throughout May 2026, with 20 distinct honeypot sources identifying the address as engaged in hacking behavior. With a confidence score of 94% and an activity frequency rating of 8 out of 10, the volume and consistency of these reports indicate persistent, deliberate scanning and intrusion attempts rather than isolated probes. The network's geographic and autonomous system context does not inherently suggest malicious intent, yet the concentration of reports from honeypot infrastructure points to automated exploitation of publicly accessible services.
Hacking activity encompasses a broad range of intrusion techniques, including vulnerability scanning, brute-force authentication attempts, and exploitation of unpatched software. The sustained frequency and elevated threat classification suggest this address systematically targets systems with known weaknesses, potentially attempting to establish unauthorized access or deploy further attack payloads. For an exposed service, such activity represents a concrete risk of credential compromise, data breach, or system compromise through unmitigated vulnerabilities.
Site operators should immediately block or rate-limit traffic from 158.173.22.20 at the network perimeter. Implementing strong authentication mechanisms, enforcing complex password policies, and enabling multi-factor authentication across accessible services significantly reduces the risk from credential-based attacks. Keeping all systems patched and up to date eliminates known vulnerabilities that this address likely attempts to exploit. Deploying intrusion detection systems and monitoring tools can automatically identify and respond to suspicious behavior patterns associated with this IP. Regular review of access logs for repeated connection attempts from this address will help identify any successful compromise attempts.