Notable Threat
IP 158.94.211.49, allocated to Omegatech LTD operating under ASN AS202412 and geolocated in the United States, represents a high-risk threat actor with a threat level of 7/10 and a confidence score of 90%, as evidenced by 2,248 total abuse reports generated across 20 automated honeypot sensors over a sustained four-month activity window from March through June 2026, with an activity frequency rating of 8/10 indicating continuous and aggressive malicious engagement.
The detection data reveals a concentrated threat pattern dominated by SMTP spam abuse alongside hacking activity, with 17 recent reports specifically categorised as Email Spam and 10 categorised as Hacking. The Suricata intrusion detection system flagged repeated "broken ack" packet anomalies during SMTP sessions, a technique frequently employed to manipulate TCP stream state and evade detection during spam transmission or reconnaissance phases. The network operator Omegatech LTD's US-based infrastructure positions this address within a jurisdiction that complicates international takedown coordination, while the sheer volume of reports over a relatively compressed timeframe demonstrates deliberate, repeated targeting rather than opportunistic scanning.
SMTP spam originating from this address poses concrete risks to recipient organisations, including inbox flooding, phishing campaign distribution, malware delivery vectors, and reputational damage to any compromised infrastructure used as a relay point. The concurrent hacking activity and stream manipulation suggest the operator may be conducting multi-vector reconnaissance or attempting to exploit vulnerable mail servers for relay abuse. The broken acknowledgment pattern detected is consistent with techniques designed to bypass basic traffic filtering or exhaust server resources, indicating a sophisticated actor rather than naive bulk mailing.
Site operators should implement robust email authentication mechanisms including SPF, DKIM, and DMARC records to validate incoming mail and prevent spoofing, deploy reputation-based email filtering services to block known hostile senders, and configure fail2ban or equivalent dynamic blocking tools to automatically quarantine sources generating excessive authentication failures. Additionally, enforcing strict SMTP transaction timeouts and enabling Suricata rules to flag malformed TCP acknowledgment sequences will help mitigate the specific attack pattern observed from this address.