High Risk
IP address 5.187.35.142 is a high-risk Dutch address operated by Amarutu Technology Ltd (ASN AS206264) that has generated 3,018 abuse reports from honeypot sensors between March and June 2026, with a dominant activity profile centered on hacking probes and web application reconnaissance.
The volume and consistency of reports make this a prolific source of automated threat activity. With a threat level of 8/10 and a confidence score of 94%, the address has been flagged across 20 separate honeypot reporting nodes. The overwhelming majority of recent reports (19 of 20 sampled) classify the activity as general hacking probes, while one report documents web application attack reconnaissance. The first and last reported dates bracket a three-month window of sustained activity, indicating persistent rather than opportunistic scanning behaviour. Geographically anchored in the Netherlands, the infrastructure is routed through Amarutu Technology Ltd, a hosting provider whose network has been associated with automated threat infrastructure in prior security research. The activity frequency score of 8/10 confirms this is not isolated noise but sustained, scripted engagement with target systems.
Hacking probes in this context refer to automated attempts to enumerate and exploit entry points across exposed services — including the identification of open ports, default credentials, and unpatched software. When combined with web application reconnaissance, this pattern strongly suggests the IP is part of a scanning or exploitation campaign targeting internet-facing applications. Attackers routinely use such automated tooling to identify vulnerable endpoints at scale before launching targeted exploitation. Even failed probes can indicate an organization is being profiled for future attacks, and any exposed service responding to these probes may leak version or configuration information useful to an adversary.
Site operators with exposed services should treat 5.187.35.142 as a confirmed malicious source and block it at the network perimeter. Implement deny-by-default firewall rules on all internet-facing interfaces, and use tools such as fail2ban or equivalent rate-limiting daemons to automatically ban IPs generating repeated authentication failures or anomalous request patterns. Audit exposed web applications for OWASP Top 10 vulnerabilities and consider deploying a web application firewall to filter probing requests before they reach application logic. Regularly review honeypot and firewall logs to identify whether the IP has attempted contact with your specific infrastructure, and ensure all internet-facing software is patched and running current versions.