Critical Alert
IP 4.197.100.161 is a critical-risk address operating from Australian network space (AS8075, MICROSOFT-CORP-MSN-AS-BLOCK) that has been extensively flagged for web application probing activity, accumulating 522 independent abuse reports with a 100% confidence score and an activity frequency rated 8 out of 10.
Detection data from 20 distinct automated honeypot sensors reveals consistent malicious scanning behaviour targeting web-facing applications, with the earliest and most recent reports both originating in January 2026. The sheer volume of reports combined with maximum confidence weighting indicates this IP has conducted sustained, systematic reconnaissance against web infrastructure rather than isolated or opportunistic scanning. The Microsoft ASN allocation is notable — cloud exit points often host both legitimate tenant traffic and abused compute resources, meaning this address may represent compromised infrastructure or a scanning platform operating from within a major cloud provider's IP range.
Web application attacks exploit vulnerabilities in internet-facing software such as cross-site scripting, file inclusion flaws, injection vectors and other OWASP Top 10 weaknesses. The dominant "web app/probe" pattern suggests automated tooling is actively fingerprinting application surfaces to identify exploitable entry points, potentially as a precursor to data exfiltration, service compromise or further lateral movement. For any organisation running HTTP/HTTPS services, an IP with this threat profile poses a concrete risk of successful exploitation if web applications remain unpatched or misconfigured.
Site operators should immediately block or rate-limit this address at the firewall or WAF layer, implement strict inbound traffic policies for cloud egress IPs, and audit web application attack surface exposure. Deploying a web application firewall with aggressive rule sets, enforcing strong authentication on all application endpoints, and monitoring logs for the scanning patterns associated with this IP will significantly reduce exposure. Tools such as fail2ban or equivalent intrusion-prevention systems can automate the blocking response based on observed probe activity.