Critical Alert
IP 103.172.204.83 is a critical-risk address operated by PT Cloud Hosting Indonesia (AS136052) in Indonesia, assessed at a threat level of 10/10 based on 160 total abuse reports dominated by SSH brute-force activity detected between September 2025 and May 2026.
Automated honeypot sensors recorded 20 independent detections of this IP engaging in credential-guessing attacks against SSH services, with additional community-sourced reports bringing the total volume to 160. The attack frequency score of 6/10 indicates sustained, repeated probing rather than a one-time scan. Fail2ban logs associated with this address documented multiple violation events against sshd, confirming an active and persistent brute-force campaign. The IP originates from Indonesian network infrastructure belonging to PT Cloud Hosting Indonesia, a hosting provider whose address space has accumulated a significant abuse footprint. The 78% confidence score reflects strong evidence alignment across detection sources, though some uncertainty remains regarding the full scope of downstream activity.
SSH brute-force attacks represent one of the most common initial-access vectors in server compromise, where threat actors systematically attempt username and password combinations to authenticate against exposed SSH daemons. Successful authentication grants direct command-line access to the target system, enabling data theft, malware deployment, lateral movement within networks, or incorporation into botnets. The sustained nature of the observed activity against IP 103.172.204.83 suggests an automated, opportunistic campaign scanning the internet for misconfigured or weakly credentialed SSH servers rather than targeted attacks against specific infrastructure.
Site operators exposing SSH services should immediately restrict authentication mechanisms to public-key cryptography, disable password-based login entirely, and configure fail2ban to automatically ban IPs exceeding defined authentication failure thresholds. Changing the default SSH port reduces automated scanning exposure, and disabling root login eliminates a high-value target account. Continuous monitoring of authentication logs for this IP address and similar sources in the same network range is recommended to identify and block emerging threats proactively.