Significant Threat
IP 143.198.225.197 is a high-risk address with a threat level of 8 out of 10, operating from DigitalOcean's network infrastructure in the United States. This IP has accumulated 7,796 abuse reports over approximately ten months, with automated honeypot sensors flagging it consistently for active hacking activity. The sustained volume of reports and elevated activity frequency score of 8 out of 10 indicate this is not an isolated incident but rather persistent hostile probing from a source that continues to target vulnerable services across the internet.
The detection data reveals that 20 separate honeypot sensors recorded connections originating from this DigitalOcean-assigned IP between September 2025 and July 2026, representing nearly a year of documented malicious activity. With a confidence score of 85 percent, analysts assess with high certainty that the observed behavior reflects deliberate intrusion attempts rather than misconfigured legitimate traffic. The AS14061 network block is frequently associated with cloud-hosted infrastructure, which threat actors commonly abuse as stepping stones for scanning and exploitation campaigns due to the relatively trusted IP reputation of major cloud providers.
The dominant threat category for IP 143.198.225.197 is hacking activity, encompassing unauthorized access attempts, exploitation of vulnerable services, and intrusion vectors such as brute-force authentication attacks. This pattern poses a concrete risk to any exposed SSH, Telnet, HTTP APIs, or other network services that lack robust access controls. The real-world danger lies in potential compromise of weakly configured systems, data exfiltration, or weaponization of compromised endpoints for further attacks against third parties. Organizations with internet-facing services should treat any connection attempt from this IP as hostile until proven otherwise.
Site operators should implement immediate defensive measures including blocking or rate-limiting traffic from this IP at the firewall level and monitoring logs for any successful authentication attempts. Deploying automated blocking tools such as fail2ban can dynamically respond to repeated connection patterns characteristic of scanning and brute-force campaigns. All exposed services should enforce strong, unique credentials and consider key-based authentication where possible. Regular patch management and intrusion detection monitoring will further reduce the attack surface that this IP and similar threats actively exploit.