Severe Risk
IP 83.168.90.16, allocated to Korbank S. A. in Poland and operating through ASN AS35179, presents a critical threat level of 10/10 based on 329 total abuse reports and an activity frequency rating of 8/10. Automated honeypot sensors recorded consistent probing activity between November 2025 and June 2026, with web application attack patterns dominating recent telemetry. This IP demonstrates a sustained, high-volume threat profile that warrants immediate blocking at the network perimeter.
The dataset reflects 20 independent threat-category reports specifically classified as web application attacks, all sourced from automated honeypot infrastructure rather than passive community submissions. The eight-month observation window from first report in November 2025 through last report in June 2026 indicates persistent scanning behaviour rather than opportunistic or time-limited exploitation. With a confidence score of 80%, analysts can reasonably conclude that the observed activity represents deliberate reconnaissance and vulnerability probing targeting web-facing services. The IP's origin within a commercial Polish ISP network does not imply legitimate use, as threat actors routinely operate from compromised endpoints or rented infrastructure within legitimate autonomous systems.
Web application attacks encompass a broad spectrum of exploitation attempts including but not limited to structured query language injection, cross-site scripting, path traversal, remote file inclusion, and other OWASP Top 10 vulnerabilities. The recorded "web app/probe" pattern suggests this address is systematically scanning internet-exposed applications to identify exploitable entry points rather than conducting single-packet probes. For organisations running unpatched or misconfigured web servers, such activity creates a direct pathway to data breach, application compromise, or backend system access. The volume and consistency of reports indicate this IP likely participates in automated campaigns that cycle through target ranges, making exposure to attack inevitable for any vulnerable endpoint.
Network operators should implement geolocation-based or ASN-scoped blocking for traffic originating from this address, as no legitimate business purpose requires inbound connections from a known hostile source. Deploying a web application firewall with rulesets tuned toOWASP Top 10 attack signatures will neutralise common exploitation vectors before they reach application logic. All publicly accessible web services should undergo immediate vulnerability assessment, prioritising patch application for known flaws in content management systems, APIs, and authentication mechanisms. Implementing fail2ban or equivalent log-analysis tools to automatically ban repeat offenders after failed request thresholds provides an additional reactive layer that complements firewall rules.