Elevated Risk
IP 185.156.73.62 is a high-risk address with a threat level of 8/10 that has generated 2,865 abuse reports from automated honeypot sensors, indicating sustained port-scanning and reconnaissance activity originating from Ukrainian network infrastructure. The volume of reports, combined with a 75% confidence score, establishes a clear pattern of hostile network probing. Detection occurred across 20 distinct honeypot sensors over approximately nine months between August 2025 and April 2026, confirming that this IP has repeatedly targeted exposed entry points across multiple environments.
The dominant threat category associated with 185.156.73.62 is port-scanning activity, supported by 14 recent reports, alongside 10 hacking-related reports. The attack-pattern evidence shows CiscoASA port-scan probes designed to identify accessible services and potential vulnerabilities in network perimeters. Additionally, Suricata intrusion-detection systems logged spurious TCP retransmission anomalies, which are consistent with reconnaissance tools that manipulate network streams to map firewall states and service availability. The network is registered to FOP Dmytro Nedilskyi, operating under ASN AS211736 within Ukrainian address space, though the geographic origin of the operator may differ from the registration data. The notably low activity-frequency score (0/10) alongside high report volume suggests this IP exhibits sporadic burst behavior rather than continuous scanning, a technique sometimes employed to evade rate-based detection thresholds.
Port scanning represents the initial phase of most targeted attacks, allowing adversaries to catalogue open services, identify outdated software, and select appropriate exploitation vectors. When paired with spurious retransmission patterns, these scans can fingerprint security appliances and determine whether packet-filtering rules are correctly configured. For an organization with exposed services, this reconnaissance provides actionable intelligence that lowers the barrier to subsequent intrusion attempts, credential guessing, or exploit delivery. The dual presence of both scanning and hacking report categories indicates that this IP has moved beyond passive enumeration toward active exploitation attempts in certain detection windows.