Maximum Danger
IP address 117.176.131.186, registered to China Mobile Communications Group Co., Ltd. on AS9808 in China, is a critical-risk address with a threat level of 10/10 and a confidence score of 96%. This IP has generated 167 abuse reports from 20 automated honeypot sensors over approximately five months, with activity first recorded in January 2026 and most recently in May 2026. The dominant threat profile is concentrated hacking activity (17 reports) and SSH brute-force intrusion attempts (3 reports), indicating sustained, high-confidence hostile behaviour against exposed services.
The volume and consistency of reports paint a clear picture of deliberate, automated targeting. Suricata alerts flagging an SSH session in progress on an expected port, combined with multiple fail2ban violation events totalling more than 50 blocked authentication attempts, confirm repeated and aggressive brute-force attempts against SSH services. The presence of a stream retransmission alert suggests the attacking client may be operating under degraded network conditions or employing evasion techniques to sustain the attack. With a 96% confidence rating and 167 independent reports across multiple sensor sources, the attribution is robust and the intent is unambiguous.
SSH brute-force attacks represent one of the most common initial-access vectors in real-world intrusions. Attackers systematically attempt credential combinations against exposed SSH daemons to gain shell access to servers, after which they may deploy backdoors, exfiltrate data or pivot deeper into a network. The sheer persistence of this IP — evidenced by dozens of blocked attempts per sensor and sustained activity over several months — signals an attacker unlikely to self-limit and extremely likely to succeed against any misconfigured or weakly authenticated target.
Any exposed SSH service should treat this IP as definitively hostile. Immediately block 117.176.131.186 at the network perimeter firewall. Enforce key-based authentication exclusively, disable root login over SSH and consider moving the service to a non-standard port. Deploy fail2ban or an equivalent dynamic blocking tool to automatically ban source IPs after a small number of failed authentication attempts. Ensure all systems are fully patched, monitor authentication logs for related activity on adjacent IPs in the same /24 range and implement rate-limiting at the network edge to reduce the effectiveness of credential-guessing campaigns.