Maximum Danger
IP 93.123.109.225 is a critical-risk address linked to 387 abuse reports from automated honeypot sensors, predominantly associated with hacking activity and confirmed exploited-host behavior originating from Bulgarian network infrastructure.
Detection data sourced from 20 automated honeypot sensors recorded activity spanning January through February 2026, with the IP traced to AS48090 operated by Techoff Srv Limited in Bulgaria. The report volume of 387 instances over approximately two months, combined with threat-category confirmations including 17 hacking-related events and 3 exploited-host classifications, indicates sustained automated offensive operations. Abstracted attack-pattern logs reference malware/exploit activity, honeypot events and attack connections consistent with systematic vulnerability probing and unauthorized access attempts. While the activity frequency metric registers at 0/10, the sheer volume of corroborating sensor reports and confirmed exploitation patterns across a compressed timeframe substantiates the elevated threat assessment despite the moderate 62% confidence score.
The dual threat classification of this address carries distinct but equally serious implications. Hacking activity encompasses intrusion attempts, vulnerability exploitation and unauthorized access vectors that could compromise exposed services directly. The exploited-host designation suggests this address may belong to a compromised system being weaponized as an attack platform without the legitimate operator's awareness, effectively functioning as infrastructure in third-party threat campaigns. Combined, these patterns indicate the address poses risks both as an active attack source and as potential evidence of broader compromised-network infrastructure requiring investigation.
Site operators should implement immediate blocking or strict rate-limiting for connections originating from this address given the 10/10 threat rating. Hardening authentication mechanisms, enforcing strong credential policies and deploying intrusion detection systems significantly reduce exposure to the brute-force and exploitation techniques associated with this activity. Maintaining current system patches and restricting unnecessary service exposure addresses the vulnerability-probing patterns observed in sensor data. Operators receiving attack connections from this IP should consider filing abuse reports with the hosting provider to potentially alert an unwitting system owner whose infrastructure may be compromised.