Maximum Danger
IP 93.123.72.166 is a critical-risk address associated with high-volume hacking activity originating from the Netherlands, with 1,133 abuse reports logged by automated honeypot sensors over approximately three months.
The IP 93.123.72.166 is registered to AS206264 (Amarutu Technology Ltd) and has been actively reported between April and June 2026, yielding a threat level of 10/10 with a 94% confidence score. Twenty separate automated honeypot sensors contributed reports, and with 1,133 total reports compressed into a short timeframe, the activity frequency rating of 8/10 indicates sustained, near-continuous engagement with target infrastructure rather than isolated scanning bursts. The dominant threat category is general hacking activity, which outpaced IoT-targeted probes by a four-to-one margin in recent reports, suggesting the actor is running a broad intrusion campaign.
General hacking activity encompasses diverse intrusion vectors including vulnerability exploitation, credential brute-forcing, and unauthorized access attempts. This pattern poses a concrete risk to any exposed service, particularly those running outdated software, weak authentication mechanisms, or accessible management interfaces. Repeated connection attempts from this address demonstrate persistent automated probing that could precede account compromise, data exfiltration, or malware delivery if left unmitigated.
Organizations should block this address at the network perimeter and implement rate-limiting on authentication endpoints to reduce brute-force exposure. Deploying fail2ban or equivalent dynamic blocking tools can automatically respond to repeated hostile patterns. All exposed services should be audited for timely patching, and administrators should verify that management interfaces are not directly internet-accessible.