High Risk
IP 78.153.140.207 is a high-risk address associated with a substantial volume of abuse reports, with Email Spam emerging as the dominant threat category. The IP, registered in the United Kingdom and operated by Hostglobal.plus Ltd (AS202306), has accumulated 2224 reports across automated honeypot sensors and community sources since first being flagged in September 2025. Despite the high report count, the activity frequency metric registers at zero, suggesting the malicious behavior may have subsided or shifted patterns in recent detection cycles. The threat level of 7/10 reflects genuine risk, though the moderate confidence score of 55% indicates some uncertainty in attributing all observed activity solely to this address.
The detection footprint spans 20 distinct honeypot sensors, a notably broad coverage that strengthens the reliability of the reported findings. The overwhelming majority of recent reports (17 of 20) classify the activity under Email Spam, with a smaller subset (3 reports) categorized as Hacking activity. This distribution paints a clear picture of the IP's primary misuse vector. The temporal span of reports runs from September 2025 through February 2026, indicating persistent or recurring abuse over approximately five months. The high report volume against a backdrop of low current activity frequency raises the possibility that automated defenses may have already begun blocking or mitigating the threat, or that the operator has altered tactics.
Email Spam activity represents a concrete risk to any organization running exposed SMTP services. Mass-distributed unwanted email frequently serves as a delivery mechanism for phishing campaigns, credential-harvesting lures, and malware payloads. Each successful spam dispatch from a compromised or abused server potentially exposes recipients to financial fraud, data theft, or ransomware infection. The Hacking reports suggest concurrent scanning or exploitation attempts targeting services beyond email infrastructure, indicating the IP may be involved in multi-vector operations rather than a single-purpose abuse case. Even if recent activity has diminished, the historical report volume demonstrates proven willingness to engage in malicious behavior.