Severe Risk
IP 83.168.90.89 is a maximum-threat-level address originating from Poland, operated by Korbank S. A. under autonomous system AS35179, with a documented history of web application probing that generated 395 total abuse reports and warrants immediate blocking by any organization running publicly accessible web services.
Automated honeypot sensors detected this address across 20 distinct detection points, with first reports dating to November 2025 and continued activity through June 2026, yielding an activity frequency rating of 8 out of 10 and a confidence score of 77 percent based on the volume and consistency of reporting. The sheer number of reports relative to the seven-month observation window indicates sustained, deliberate scanning behavior rather than opportunistic or transient activity, and the geographic origin within Poland's network infrastructure through a regional ISP suggests this is not a compromised residential endpoint but potentially a dedicated scanning or attack infrastructure. The dominant threat category identified in recent reports is web application attacks, specifically probes targeting web-facing applications for known vulnerabilities.
Web application attacks encompass exploitation attempts against vulnerabilities listed in the OWASP Top 10, including cross-site scripting, cross-site request forgery, remote and local file inclusion, SQL injection, and authentication bypass against web servers, content management systems, or custom applications. An IP with 395 reported incidents of this activity poses a direct risk to any HTTP or HTTPS service exposed to the internet, as successful exploitation can lead to data breach, server compromise, malware distribution, or use of the target as a pivot point for further network intrusion. The 77 percent confidence score reflects that while the threat pattern is clear, attribution to a specific threat actor or campaign cannot be definitively confirmed from available telemetry.
Network defenders should block this address at the firewall or edge device level given the maximum threat rating, implement rate-limiting on authentication and form-submission endpoints to disrupt automated attack tooling, and deploy or harden a web application firewall to inspect and block common web attack signatures. Regular review of access logs for requests originating from this IP or adjacent address ranges will help identify any attempted exploitation, and tools such as fail2ban or equivalent dynamic blocking systems can automate response to repeated hostile probes from this source.