Elevated Risk
IP 45.144.212.169, allocated to Kprohost LLC in Ukraine and operating through ASN AS214940, represents a moderate-to-high risk address associated primarily with SMTP spam abuse and anomalous network packet anomalies detected across multiple automated honeypot sensors. The IP has accumulated over two hundred reports from community and sensor feeds since early 2026, with the most recent activity documented in April 2026. Despite a moderate threat level assessment, the confidence in malicious attribution remains imperfect, and the reported activity frequency remains low, suggesting either intermittent exploitation patterns or coordinated campaigns with extended dormant periods between engagement cycles.
Detection data reveals that automated honeypot infrastructure across twenty distinct sensors flagged this address repeatedly, capturing SMTP spam and abuse patterns alongside Suricata stream-layer anomalies involving malformed acknowledgment packets. The co-occurrence of broken TCP acknowledgment packets with email spam activity is a known technique employed to evade basic traffic filtering and stateless inspection, as fragmented or improperly constructed stream-state data can cause detection systems to misclassify or drop suspicious payloads. The concentration of activity within Ukraine's network infrastructure aligns with broader trends of compromised hosting environments being leveraged for mass email distribution and scanning operations, particularly within smaller regional providers where abuse management may be less rigorous.
The primary threat vectors associated with 45.144.212.169 centre on email spam distribution, which encompasses advertising campaigns, phishing payloads, and malware delivery mechanisms that exploit end-user trust in seemingly legitimate correspondence. The secondary hacking classification indicates scanning and intrusion-probing behaviour, likely reconnaissance for identifying vulnerable SMTP configurations or exploited open-relay opportunities. While the activity frequency score suggests the address is not currently in an aggressive sustained campaign, the combination of stream-level evasion techniques and spam infrastructure positioning means any exposed mail service or unpatched SMTP daemon could face immediate risk of compromise or relay exploitation.