Critical Alert
IP 4.145.113.4, registered to Microsoft Azure infrastructure in Singapore, is a maximum-threat-level address that has generated 1,486 independent abuse reports across automated honeypot sensors since September 2025, making it one of the most actively maligned cloud-hosted IPs observed in that period. With a threat level of 10/10 and a confidence score of 94%, this address demonstrates consistent, high-volume hacking activity characterised by repeated intrusion attempts and exploitation probing against exposed services. The sustained activity frequency rating of 8/10 across a ten-month window indicates persistent, automated assault rather than opportunistic scanning.
The detection data reveals a concentrated pattern of hacking behaviour, with all 20 most recent report categories exclusively citing intrusion-related activity. Operating from AS8075 (Microsoft-Corp-MSN-AS-Block) in Singapore, this IP leverages cloud infrastructure that can rapidly provision and rotate IP space, complicating reputation-based blocking alone. The exclusive reliance on honeypot sensor detection across all 1,486 reports confirms these are not isolated incidents but systematic, ongoing campaigns that have triggered repeated alerts in diverse sensor environments worldwide.
The dominant hacking classification encompasses unauthorized access attempts, vulnerability probing, and exploitation of misconfigured or outdated services. This IP represents a concrete risk to any exposed SSH, RDP, web interfaces, or unpatched applications, particularly those with weak credential policies or known vulnerabilities. The volume and persistence of reports suggest this address is likely part of an automated botnet or mass-scanning operation that systematically catalogues and attempts to compromise exposed attack surfaces.
Site operators should immediately block or rate-limit connections from this address at the firewall or load-balancer level, implement fail2ban or equivalent automated blocking tools to harden SSH and remote access services, enforce strong multi-factor authentication on all administrative interfaces, and audit publicly exposed services for unnecessary exposure. Regular patching, intrusion detection monitoring, and reviewing authentication logs for patterns matching this IP's activity will further reduce risk exposure.