High Risk
IP 81.168.83.103, registered to Iomart Cloud Services Limited in the United Kingdom, presents a high-risk threat profile with a threat level of 8/10 and an 87 percent confidence score based on 723 total abuse reports. The address was first reported in January 2026 and remains active, with the most recent reports filed in May 2026, indicating persistent hostile behavior over a multi-month window.
Detection activity was generated by 20 automated honeypot sensors, which logged both general hacking probes and targeted web application reconnaissance. The dominant threat categories are hacking activity at 19 reports and web application attacks at 11 reports. Network-level analysis reveals Suricata intrusion detection alerts identifying malformed TCP stream packets with broken acknowledgments alongside repeated web application probing patterns, suggesting automated scanning toolkits rather than opportunistic single-attempt intrusions.
The combination of hacking probes and web application attacks reflects common reconnaissance and exploitation patterns where threat actors systematically enumerate exposed services and vulnerabilities. The malformed packet anomalies indicate potential TCP-level fingerprinting attempts to evade detection or exploit stateful inspection weaknesses, while web application probes suggest interest in exploiting OWASP Top 10 vulnerabilities. The volume of reports over five months demonstrates sustained intent rather than transient scanning, elevating real-world risk to any directly exposed services.
Site operators should block or rate-limit this IP address at the firewall level, deploy or configure a web application firewall to mitigate probing attempts, and implement fail2ban or equivalent log-based blocking tools. Maintaining strict patching schedules, enforcing strong authentication on exposed services, and monitoring for the specific Suricata stream anomalies observed will reduce exposure to the techniques this address has demonstrated.