Substantial Risk
IP 110.10.176.224 is a high-risk address operating from South Korea through SK Broadband's AS9318 network, with a threat level of 8/10 driven by 376 total abuse reports spanning hacking intrusion attempts and VoIP telephony fraud over a concentrated two-month detection window from automated honeypot sensors.
The IP has accumulated 376 community and sensor reports since first appearing in March 2026, with its most recent activity logged in May 2026, yielding an exceptionally high activity frequency rating of 8/10. Detection across 20 separate automated honeypot sensors confirms sustained, multi-vector hostile activity rather than isolated probes. The dominant threat categories are Hacking (13 recent reports) involving general intrusion and exploitation attempts, and Fraud VoIP (7 recent reports) indicating attempts to compromise or abuse voice-over-internet infrastructure for financial gain. Suricata intrusion detection systems additionally flagged anomalous application-layer traffic patterns consistent with unauthorized protocol manipulation. The 94% confidence score and volume of independent sensor reports strongly support the assessment that this address represents a genuine, persistent threat actor rather than misclassified or transient traffic.
The Hacking activity associated with this IP reflects ongoing attempts to gain unauthorized access to target systems through vulnerability exploitation and intrusion techniques, posing direct risks to any exposed services such as remote administration interfaces, web applications, or database endpoints. The concurrent VoIP fraud signals suggest this actor may be targeting telephony infrastructure to route unauthorized calls, typically to premium-rate numbers for revenue generation, which can result in significant financial losses for compromised organizations and telecom providers. The combination of both threat vectors indicates a capable adversary pursuing multiple monetization strategies simultaneously, with honeypot detection patterns revealing Suricata application-layer anomalies suggesting the traffic involves protocol-level manipulation or malformed requests designed to evade basic detection.