Critical Alert
IP 185.93.89.191 is a critical-risk address originating from Iran that has generated 360 abuse reports across 20 automated honeypot sensors since March 2026, with a dominant pattern of hacking activity alongside IoT/ICS targeting and SOCKS5 authentication brute-force attempts, yielding a threat-level score of 10 out of 10 at 94 percent confidence.
The volume of reporting is substantial for the two-month observation window, averaging roughly 180 reports per month, and the activity frequency rating of 8 out of 10 confirms persistent, aggressive scanning and intrusion activity. All 20 detection sources are automated honeypot sensors, indicating this address systematically probes network defenses across multiple targets. The associated network, AS213790 operated by Limited Network LTD, has been flagged for coordinated hostile activity concentrated in the Iranian region, and the confidence score of 94 percent reflects highly consistent behavior across multiple independent sensor feeds.
The dominant hacking category encompasses general intrusion attempts and exploitation of vulnerabilities, while the secondary IoT and ICS targeting pattern reveals a specific focus on smart devices, cameras, routers, and industrial control systems that frequently ship with weak default security configurations. The SOCKS5 brute-force component indicates systematic credential-guessing against proxy authentication systems, a tactic that can establish footholds for further network propagation. Together, these patterns suggest an actor pursuing both mass IoT compromise and targeted authentication compromise against exposed services.
Site operators should implement network segmentation to isolate IoT and ICS devices from critical infrastructure, apply firmware updates promptly, and replace default credentials on all networked devices. Rate limiting and account lockout policies should govern authentication endpoints, and multi-factor authentication should be enforced wherever feasible. Deploying defensive tools such as fail2ban can automate temporary blocking of repeated brute-force source IPs, while maintaining intrusion detection signatures tuned to SOCKS5 authentication probing patterns provides additional alerting coverage.