Significant Threat
IP 184.105.139.70, allocated to Hurricane Electric's AS6939 network in the United States, presents a maximum threat level of 10/10 with an 87 percent confidence score, supported by 476 independent abuse reports and a sustained activity frequency rated 8 out of 10. Automated honeypot sensors recorded this address conducting multiple simultaneous threat categories, including unauthorized intrusion attempts, targeted exploitation of Internet of Things infrastructure, port-scanning reconnaissance, and confirmed exploitation of at least one victim host. The breadth and persistence of this activity, spanning August 2025 through June 2026, indicate a deliberate and systematic assault campaign rather than opportunistic scanning.
The evidence base for this assessment is robust: 20 separate automated honeypot sensors filed reports detailing the address's behavior, with Hacking attempts accounting for the majority of recent classifications, followed by IoT-targeted activity and port-scanning operations. Specific attack patterns documented against honeypot infrastructure include Redis protocol exploitation attempts and reconnaissance probes using Zmap User-Agent strings designed to identify vulnerable devices. The port-scanning activity, detected through Suricata rulesets, demonstrates classic reconnaissance behavior wherein the address systematically surveys target networks for open services prior to launching exploitation attempts. This combination of reconnaissance and active exploitation targeting represents a mature, multi-stage attack methodology.
The real-world risk posed by 184.105.139.70 extends beyond mere noise. Port-scanning reconnaissance directly informs subsequent targeted attacks by mapping exposed services and vulnerabilities. Redis exploitation attempts can yield complete server compromise, data exfiltration or weaponization of the host for later attacks. IoT-targeted operations specifically prey on devices with weak default configurations and unpatched firmware, which often lack adequate logging and may serve as persistent beachheads within enterprise networks. The diversity of techniques observed suggests the operator behind this IP possesses sophisticated capabilities and adapts tactics based on detected responses.