Maximum Danger
IP 122.155.28.15 is a critical-risk address registered in Thailand that has been flagged across multiple automated honeypot sensors as an exploited host actively engaged in malware and exploit activity, with 727 abuse reports filed against this single IP and a threat-level score of 10 out of 10. The volume and consistency of these reports, combined with a 94 percent confidence rating and an activity frequency rated 8 out of 10, indicate sustained malicious behaviour originating from this address rather than isolated incident. Network attribution points to AS9335, operated by National Telecom Public Company Limited, suggesting the compromised infrastructure sits within a Thai telecommunications provider's allocation.
Community and sensor reporting data spanning February 2026 document this IP as an exploited host in 20 recent submissions, with the broader dataset of 727 total reports indicating persistent involvement in hostile operations over an extended period. The detection footprint across 20 separate automated honeypot sensors demonstrates that this address is not merely probing randomly but is actively communicating with and targeting vulnerable honeypot infrastructure across multiple reporting nodes. The attack-pattern analysis flags malware and exploit activity, meaning the compromised system is being weaponised to scan for vulnerabilities, propagate malicious payloads or attempt to compromise other networked resources without the knowledge of its legitimate operator.
An exploited host represents a concrete operational risk because it functions as an unwitting attack platform, often operating at higher volumes and from geographic locations that bypass simple geo-blocking defences. Attackers routinely compromise consumer and enterprise endpoints to obfuscate their origin, leverage legitimate ISP infrastructure and evade reputation-based blocking lists. The sustained frequency of activity from IP 122.155.28.15 suggests it remains under attacker control, meaning any organisation exposing services to Thai IP ranges may continue encountering automated exploit attempts, credential-brute-force campaigns or malware delivery originating from this address. The absence of geographic diversity in the reporting window also indicates the threat actor has maintained persistent access to this host.