Substantial Risk
IP 207.90.244.27 is a high-risk address originating from the United States on Cogent Communications' network (AS174) that has generated 9,768 abuse reports from automated honeypot sensors over approximately nine months of active observation, indicating sustained and widespread malicious activity consistent with large-scale intrusion attempts.
The threat level of 8 out of 10 combined with an activity frequency rating of 8 out of 10 reflects highly consistent malicious behaviour detected across 20 independent automated honeypot sources, producing an 87% confidence score in the assessment. The observation window spans from September 2025 to June 2026, encompassing roughly nine months of continuous reporting. All reported threat categories during this period centered exclusively on hacking activity, encompassing various forms of unauthorized access attempts and exploitation techniques. The sheer volume of reports relative to the observation period indicates this address participates in persistent, automated scanning or attack campaigns rather than isolated opportunistic probes.
Hacking activity encompasses a broad spectrum of intrusion methodologies including vulnerability enumeration, exploitation of unpatched services, and credential-based attack vectors targeting exposed network endpoints. The sustained report volume and frequency suggest this address likely operates as part of coordinated scanning infrastructure or bot-assisted operations systematically probing internet-facing systems worldwide. For organizations running exposed services, such traffic represents an ongoing reconnaissance and exploitation threat requiring proactive defensive measures.
Site operators should implement blocking or strict rate-limiting for this address at network perimeters, deploy intrusion detection systems to identify associated attack patterns, enforce multi-factor authentication on all remote access services, and ensure critical systems receive prompt security patching. Automated tools such as fail2ban can help dynamically respond to repeated hostile connection attempts originating from this source.