High Risk
IP 46.151.178.13 is a high-risk address operated by Sino Worldwide Trading Limited under ASN AS211443 that has generated 3,689 abuse reports across automated honeypot sensors between February and July 2026, presenting a significant and persistent threat primarily targeting internet-of-things infrastructure.
With a threat level of 8/10 and an activity frequency rated at 8/10, this Netherlands-hosted IP address demonstrates a sustained campaign of malicious activity spanning approximately five months. The volume of reports — averaging roughly 738 per month across 20 distinct honeypot detection points — indicates systematic, automated scanning rather than opportunistic probing. Suricata intrusion-detection systems logged the dominant pattern as "SURICATA Applayer Wrong direction first Data," a signature often associated with protocol-level exploitation attempts and misdirected connection sequences used to fingerprint or bypass security appliances. The IP's 89% confidence score reflects strong corroboration across multiple independent detection sources, confirming this is not transient noise but an established threat actor operating from a commercial hosting environment.
The dual focus on hacking activity and IoT targeting reveals an attacker prioritising vulnerable connected devices — routers, cameras, smart sensors and other endpoints frequently deployed with weak default credentials and unpatched firmware. IoT-targeted campaigns allow threat actors to build botnets, establish persistentfootholds in residential or corporate networks, and pivot toward higher-value systems. The "attack connection" and "honeypot event — IoT targeted" patterns observed in reports confirm active exploitation attempts rather than passive reconnaissance, meaning exposed IoT deployments face immediate risk of compromise if this address is not blocked.
Site operators should immediately block or rate-limit connections from 46.151.178.13 at the network perimeter firewall, and consider implementing automated blocking via defensive tools such as fail2ban to respond to repeated probe patterns. IoT device segmentation using VLANs is strongly recommended to isolate smart devices from critical infrastructure. All connected devices should run current firmware, have default credentials replaced with strong unique passwords, and have Universal Plug and Play disabled at the router level. Continuous monitoring of authentication logs for source IPs associated with this address will help identify any successful intrusion attempts before data exfiltration occurs.