Maximum Danger
IP 87.251.64.146 is a critical-risk exploited host responsible for malware and exploit activity, with an overwhelming 4,012 abuse reports filed across a three-month window between April and July 2026. This address presents a near-certain threat to any exposed service, operating as a compromised platform weaponized by threat actors without the legitimate operator's knowledge or consent.
The sheer volume of reports filed against 87.251.64.146 sets this address apart from routine scanner traffic. Automated honeypot sensors across 20 distinct detection points recorded this activity, establishing a 98% confidence score that this traffic represents genuine malicious behaviour. With an activity frequency rating of 8 out of 10, the IP demonstrates persistent, repeated offending rather than isolated probe attempts. The address traces to AS200730 under operator ISAEV Igor in the United States, though the exploited-host classification confirms the legitimate owner is an unknowing victim whose infrastructure has been co-opted for offensive operations.
An exploited-host designation indicates the system at this address has been compromised, typically through unpatched vulnerabilities, weak credentials or malware infection, transforming it into an unwitting attack platform. The concrete risk to exposed services is significant: this compromised host can be leveraged to launch distributed attacks, serve malicious payloads, conduct reconnaissance against other targets or relay traffic to obscure the true origin of an operation. Defenders who encounter this IP should treat any associated traffic as hostile, regardless of the apparent protocol or service, because the compromised machine may be running attacker-controlled scripts designed to exploit specific application weaknesses.
Site operators should immediately block 87.251.64.146 at the network perimeter and monitor for any follow-on activity from adjacent address ranges within AS200730. Implementing fail2ban or equivalent dynamic firewall rules can automatically drop future connections from this source. Organizations running publicly accessible services should enforce strong, unique credentials and multi-factor authentication to reduce the risk of becoming similarly compromised. Finally, consider submitting an abuse report to the hosting provider to facilitate remediation of the exploited system, which benefits the broader internet community by returning a compromised asset to its rightful owner.