Substantial Risk
IP 65.49.1.122 is a high-risk address originating from the United States within Hurricane Electric's network (AS6939), linked to widespread hacking activity and assessed at an 8/10 threat level with an 88% confidence rating based on 532 documented abuse reports from automated honeypot sensors.
The IP has been under continuous observation since August 2025 with recent activity confirmed through June 2026, representing roughly eleven months of persistent hostile probes detected by 20 separate honeypot sensors. Report volume and activity frequency both score 8/10, indicating sustained, high-volume malicious traffic rather than isolated incidents. The dominant threat category is general hacking activity (18 recent reports), supplemented by isolated incidents of IoT targeting and exploited host behavior, suggesting this address conducts multiple intrusion technique variations across victim infrastructure.
Hacking activity encompasses unauthorized access attempts, vulnerability exploitation and intrusion campaign operations against exposed services. When combined with IoT targeting patterns, this indicates the address systematically scans and probes networked devices with weak security configurations, potentially cataloguing vulnerable systems for subsequent compromise. The presence of exploited host classification suggests some activity may originate from previously compromised machines co-opted into broader attack infrastructure, which complicates attribution and defense. Services exposed to the internet face concrete risk of credential compromise, malware delivery or recruitment into botnets when targeted by such activity.
Site operators should block IP 65.49.1.122 at the network perimeter and implement fail2ban or equivalent dynamic firewall rules to automatically reject repeated connection attempts. Exposed services should enforce strong authentication, apply patches promptly and restrict access to administrative interfaces. Network segmentation isolating IoT devices and internal resources reduces the impact of successful reconnaissance. Monitoring logs for the patterns "attack connection" and "IoT targeted" behavior across honeypot and firewall data helps identify ongoing targeting campaigns targeting your infrastructure.