Maximum Danger
93.123.72.166 is a critical-risk IP address with a threat level of 10/10 that has accumulated 1051 abuse reports from automated honeypot sensors, with the majority of recent activity classified as hacking attempts and IoT-targeted exploitation against connected devices.
The IP routes through AS206264 operated by Amarutu Technology Ltd in the Netherlands and has shown persistent malicious activity between April 2026 and June 2026, generating a confidence score of 94 percent across 20 distinct honeypot reporting sources. The activity frequency score of 8/10 indicates near-continuous engagement with target infrastructure during this three-month window, and a Suricata intrusion-detection alert specifically flagged connections carrying invalid timestamps—a common signature of automated attack tooling designed to bypass basic session-validation controls. The combination of high report volume, multiple independent detection points, and a sustained detection timeframe establishes this address as a consistently active threat actor within the scanning ecosystem.
The dominant threat category for 93.123.72.166 centers on unauthorized access attempts and exploitation of internet-connected devices, including smart cameras, routers, and other IoT hardware that frequently ship with weak default configurations. Attackers leverage such devices to establish persistent footholds, pivot through networks, or aggregate them into botnets. The presence of IoT-targeted patterns alongside general hacking activity suggests this actor employs reconnaissance and exploit workflows tailored to consumer-grade connected hardware, which often lacks robust firmware update mechanisms and remains exposed to the public internet with factory-default credentials intact.
Site operators who discover this IP in their logs should treat it as a confirmed hostile source and implement immediate blocking at the network edge or firewall level. Deploying automated dynamic blocking tools such as fail2ban or equivalent rate-limiting solutions will reduce the effectiveness of repeated connection attempts. Network segmentation isolating IoT devices from critical systems limits the blast radius of any successful compromise, and auditing all internet-facing services for unnecessary exposure while enforcing strong unique credentials and disabling unused protocols substantially reduces the attack surface available to this actor.