Notable Threat
IP 207.90.244.11, registered to the COGENT-174 autonomous system in the United States, is a high-risk address with a threat level of 8/10 and an 88% confidence score, primarily linked to sustained hacking activity detected across 20 automated honeypot sensors over approximately ten months from September 2025 through July 2026. The volume of 2,745 total abuse reports combined with an activity frequency rating of 8/10 indicates persistent, repeated offensive operations originating from this IP rather than isolated probing.
The overwhelming majority of recent reports — 18 of the 20 most recent categorizations — classify the observed behaviour as general hacking activity, encompassing intrusion attempts, vulnerability exploitation and unauthorized access vectors. The detection signatures include Suricata alerts flagging asymmetric protocol detection, malware and exploit activity patterns, and attack connection attempts. One additional report tied this address to VoIP fraud, while another classified it as an exploited host, suggesting that either the IP itself or an associated infrastructure component may have been compromised and weaponized by threat actors without the owner's knowledge.
The concentration of hacking-focused reports signals an active scanning and intrusion infrastructure rather than opportunistic noise. An IP with this reputation operating within a major US ISP backbone presents a credible risk to any exposed service — particularly SSH, Telnet, SIP and HTTP endpoints — that accepts connections from Cogent-peered networks. The presence of exploited-host classification raises the possibility that this address may be rotating through compromised residential or cloud endpoints, complicating straightforward attribution.
Site operators should treat connections from IP 207.90.244.11 as hostile by default. Implement robust rate-limiting and fail2ban-style authentication hardening on exposed services, enforce SIP ALG disabling where VoIP is not required, and block this address at the network perimeter. Regularly review Suricata or equivalent IDS logs for protocol anomalies matching the reported signatures, and consider filing an abuse report with Cogent Communications referencing the sustained scanning pattern to facilitate potential upstream action.