Severe Risk
IP 106.75.157.47 is a high-risk address with a maximum threat score of 10 out of 10 and near-certain confidence, linked exclusively to general hacking activity including intrusion attempts, vulnerability exploitation and unauthorized access scanning. The IP has accumulated 602 abuse reports over approximately ten months, with activity detected consistently across twenty automated honeypot sensors, indicating sustained and widespread hostile behavior originating from this single source.
Geolocated to China and operating within AS58466 under CHINANET Guangdong province network, this address was first reported in September 2025 and most recently reported in June 2026, demonstrating persistent malicious activity across an extended timeframe. The exceptionally high report volume of 602 incidents combined with an activity frequency rating of 8 out of 10 confirms this is not isolated or opportunistic scanning but rather sustained, deliberate targeting of exposed services. All 602 reports consistently categorize the activity under the "Hacking" umbrella, encompassing various forms of intrusion attempts rather than a single attack vector.
The "Hacking" classification for this IP indicates the operator is conducting automated vulnerability probing, brute-force authentication attempts and exploitation trials against services exposed to the internet. This pattern poses a concrete risk to any internet-facing systems, particularly those with weak authentication configurations, unpatched software or exposed administrative interfaces. Even unsuccessful attempts consume server resources and may serve as reconnaissance for more sophisticated follow-on operations.
Site operators should implement immediate defensive measures including blocking or rate-limiting traffic from this IP at the firewall level, hardening authentication mechanisms with strong password policies and multi-factor authentication, and deploying intrusion detection systems such as fail2ban to automatically ban repeat offenders. Regular security audits, prompt patching of known vulnerabilities and monitoring logs for repeated connection patterns from this address will further reduce exposure to the persistent scanning behavior documented against IP 106.75.157.47.