Cautionary Risk
IP 91.209.135.33 is a medium-risk address registered in Georgia and operated by Cloud Hosting Solutions, Limited that has accumulated 160 total abuse reports, with Email Spam accounting for the most recent threat category submissions from automated honeypot sensors.
Analysis of the available data reveals that all recent reports — 20 distinct submissions — were generated by automated honeypot sensors and attributed specifically to SMTP spam and abuse patterns. The IP was first and last reported during October 2025, indicating a concentrated period of observed malicious activity on this single network. With a confidence score of 58% and an activity frequency rating of 0/10, the data suggests periodic rather than continuous engagement with target systems, which is consistent with probing or opportunistic spam campaigns that vary their output to evade detection thresholds. The AS199785 autonomous system is operated by Cloud Hosting Solutions, Limited, a hosting provider whose infrastructure may be shared among multiple customers, meaning the source of the spam activity could originate from a single compromised tenant or a purposely provisioned abuse vehicle. The total report volume of 160 incidents across all categories indicates sustained attention from detection systems over time.
Email Spam campaigns exploiting SMTP infrastructure represent a concrete threat to any organization operating publicly accessible mail servers. Mass-distributed spam serves as a delivery mechanism for phishing lures, credential-harvesting schemes and malware payloads, and even a small volume of successfully delivered messages can result in significant financial or data losses for recipients. When an IP address develops a poor reputation through spam activity, it risks inclusion on real-time blocklists, which can disrupt legitimate outbound email delivery for the IP's entire network segment and create downstream reputation damage that persists beyond the immediate abuse window.
Site operators should implement SPF, DKIM and DMARC authentication protocols to validate legitimate sending sources and make SMTP abuse more difficult. Deploying reputable email filtering services and configuring automated response rules using tools such as fail2ban can block repeated connection attempts from known bad actors. Restricting SMTP relay to authenticated users only and enforcing strict connection rate limits will further reduce exposure to spam distribution attempts originating from this address.