Severe Risk
IP 185.93.89.193 is a critical-risk address with a threat level of 10/10 and 94% confidence, originating from Iran and operated by Limited Network LTD via ASN AS213790. This IP has accumulated 362 abuse reports from automated honeypot sensors, with a notably high activity frequency of 8/10, making it one of the most hostile addresses observed in recent threat intelligence. The dominant threat category is general hacking activity, supplemented by targeted IoT exploitation attempts and SOCKS5 brute-force operations. First reported in March 2026 and still active as of April 2026, this address represents a persistent, multi-vector threat to any exposed service.
The volume and consistency of reports indicate sustained, deliberate hostile activity rather than opportunistic scanning. All 362 incidents were detected through automated honeypot sensors, with 20 distinct sensor sources contributing reports over a concentrated two-month window. The IP's activity frequency score of 8/10 reflects continuous engagement with target systems, suggesting an automated or semi-automated campaign rather than isolated manual probes. The specific attack patterns observed include generic attack connections, IoT-targeted reconnaissance, and SOCKS5 brute-force authentication attacks. Limited Network LTD, the network operator, operates within Iran's telecommunications infrastructure, and the sustained nature of this activity indicates resources and intent consistent with organized threat operations.
The SOCKS5 brute-force activity observed from this address represents a concrete authentication attack vector. Attackers systematically attempt credential combinations against SOCKS5 proxy services, potentially seeking to compromise relay infrastructure for anonymized further attacks or data exfiltration. The IoT-targeted activity follows a well-documented pattern of exploiting weak security in connected devices such as cameras, routers, and smart sensors, often leveraging default credentials or unpatched firmware vulnerabilities. Combined with general hacking probes, this address presents a multi-layered threat capable of both compromising authentication systems and exploiting the notoriously weak security posture of IoT deployments exposed to the internet.