Significant Threat
IP address 207.90.244.23 is a high-risk address associated with persistent hacking activity, originating from Cogent Communications infrastructure in the United States. With 684 abuse reports logged against it and a threat level of 8/10, this IP has been reliably flagged by automated honeypot sensors over a concentrated detection window spanning September through November 2025. The volume of reports far exceeds typical background noise levels seen on internet-facing systems, placing it well within the upper percentile of reported malicious actors for its geographic region and network operator.
The detection data reveals a consistent pattern of intrusion-oriented activity attributed entirely to the hacking category, with 20 recent reports corroborating this classification across multiple sensor sources. The network operator, Cogent-174 (AS174), is a major tier-one internet service provider whose IP space is frequently repurposed by threat actors due to the sheer volume of customers and the difficulty in coordinating takedowns across such large address allocations. The activity frequency metric of 0/10, combined with a September–November 2025 reporting window, suggests this IP was highly active during that period but has since quieted—though the 684 cumulative reports indicate a sustained campaign rather than a brief probe.
The hacking classification encompasses systematic intrusion attempts, vulnerability exploitation, and unauthorized access scanning directed at exposed services. For any organisation running open SSH, RDP, web interfaces, or database ports, such an IP represents a direct pathway to compromise if left unguarded. The real-world risk is not theoretical: automated exploitation toolkits routinely cycle through dictionaries of weak credentials and known CVEs against every reachable host, and even a single successful foothold can enable lateral movement, data exfiltration, or ransomware deployment within minutes. The 67% confidence score indicates some detection ambiguity, likely due to the use of common scanning tools that overlap with legitimate penetration-testing signatures, but the report volume anchors the assessment firmly in hostile territory.