Significant Threat
IP 89.42.231.184 is a high-risk address associated with 301 independent abuse reports from automated honeypot sensors, predominantly linked to general hacking activity and web application probing, originating from Amarutu Technology Ltd's network in the Netherlands. With a threat level of 8/10 and reports spanning January through February 2026, this IP demonstrates a credible pattern of malicious reconnaissance and intrusion attempts against exposed services. The detection confidence of 64% reflects substantial but not overwhelming evidence, consistent with an actor employing varied techniques to evade simple blocklists.
Analysis of the 301 reports reveals a focused threat profile dominated by hacking-related activity, accounting for the vast majority of recent submissions, complemented by isolated web application attack signatures and at least one instance classified as an exploited host. The IP was flagged by 20 separate automated honeypot sensors, indicating distributed detection coverage rather than a single-point false positive. Observed attack patterns include generic connection attempts, probes targeting web application infrastructure, and activity consistent with malware or exploit delivery. The network operator, Amarutu Technology Ltd, is a hosting provider based in the Netherlands, a jurisdiction frequently exploited by threat actors due to its robust infrastructure and relatively permissive abuse-handling turnaround times.
The dominant hacking classification encompasses unauthorized access attempts, vulnerability scanning, and exploitation of known weaknesses in exposed services, representing a direct pathway to system compromise if successful. Web application attacks similarly target application-layer weaknesses such as those identified in the OWASP Top 10, potentially enabling data exfiltration, session hijacking, or further network penetration. The presence of an exploited host classification suggests this IP may at times be operating from a compromised infrastructure element, compounding attribution challenges and indicating possible participation in larger botnet or proxy networks used to obfuscate attack origins.