Elevated Risk
IP 209.38.70.156 is a high-risk address operated through DigitalOcean's AS14061 infrastructure in the United States, linked to sustained hacking activity with 8,718 abuse reports and a threat level of 8 out of 10. The IP has been flagged by automated honeypot sensors as actively engaging in intrusion attempts since September 2025, with its most recent detection occurring in July 2026, indicating a persistent multi-month campaign against exposed services.
The volume of reports associated with this address is substantial, with 20 confirmed hacking-category incidents and a single IoT-targeted connection recorded across the detection network. The activity frequency score of 8 out of 10 reinforces that this is not an isolated or opportunistic probe but rather a deliberate and repeated offensive operation. The 85% confidence score reflects strong evidentiary agreement across multiple sensor sources, though the possibility of address spoofing or NAT-related false attribution cannot be entirely excluded given cloud provider infrastructure. DigitalOcean's ASN is frequently abused as a staging ground for such activity due to its accessibility and flexible provisioning model, making this IP's presence within that network contextually significant for defenders.
The dominant hacking activity represents general intrusion attempts including vulnerability exploitation and unauthorized access probing against exposed attack surfaces. When combined with the IoT-targeted connection, this pattern suggests the operator may be conducting reconnaissance across both traditional server infrastructure and connected devices. Real-world risk includes compromised credentials, deployed malware, data exfiltration, or the incorporation of targeted systems into botnet operations. The sustained nature of the activity over approximately ten months demonstrates resources and intent consistent with an organized threat actor rather than casual scanning.
Defenders should block or heavily rate-limit traffic from this IP at the network perimeter, deploy fail2ban or equivalent log-based blocking tools to automatically respond to authentication failures, and enforce strong credential policies including multi-factor authentication on all externally accessible services. Regular patching of internet-facing software and segmentation of IoT devices from critical infrastructure will reduce the effectiveness of any successful intrusion attempts originating from this or similar addresses.