Significant Threat
IP 137.184.112.103 is a high-risk address assessed at threat level 8/10 that has accumulated 1,926 abuse reports over approximately eight months, indicating persistent and aggressive hostile activity originating from DigitalOcean's infrastructure in the United States.
The IP was first reported in November 2025 with the most recent reports logged in July 2026, demonstrating continuous malicious behavior across an eight-month observation window. Detection occurred through 20 separate automated honeypot sensors, yielding a confidence score of 87% and an activity frequency rating of 8/10. The dominant threat category was Hacking activity, accounting for 19 of the recent reports, while IoT-targeted attacks comprised a smaller but notable portion. The address operates on AS14061 (DigitalOcean ASN), meaning the traffic originates from a major cloud hosting provider frequently abused by threat actors to mask their origin and scale their operations globally.
Hacking activity encompasses a broad range of intrusion attempts, vulnerability exploitation, and unauthorized access campaigns. Combined with the IoT/ICS targeting pattern observed in honeypot telemetry, this IP appears to be actively scanning and probing for vulnerable networked devices, misconfigured services, and exploitable entry points across the internet. The volume of reports relative to the detection window suggests systematic, automated reconnaissance rather than opportunistic probing. An attacker leveraging this address could target weak authentication on IoT devices, default credentials on networked hardware, or unpatched services for initial access, potentially assembling compromised endpoints into botnets or pivoting into deeper network segments.
Site operators should block or aggressively rate-limit traffic from this address at the firewall or load balancer level, implement strict authentication requirements on all exposed services, and configure monitoring alerts for connections originating from this source. Organizations with IoT or operational technology infrastructure should segment these systems from general corporate networks, enforce strong unique credentials on every device, maintain current firmware updates, and consider deploying intrusion detection signatures tuned to common IoT exploit patterns. Tools such as fail2ban can supplement blocklists by dynamically banning hosts exhibiting brute-force behavior.