Extreme Threat
IP address 213.209.159.227 is a high-risk threat actor with a maximum 10/10 threat level and near-certain 98% confidence score, primarily engaged in active hacking operations targeting SSH services on non-standard ports. With 161 total abuse reports concentrated between April and May 2026, this address demonstrates sustained offensive behavior at an 8/10 activity frequency across automated honeypot detection systems.
Suricata intrusion-detection sensors flagged this address for SSH sessions on unusual ports, a technique commonly used by threat actors to evade standard security monitoring and target exposed management interfaces. All 161 reports originate from automated honeypot sensors, with the address geolocated to Taiwan and routed through AS208137 (Feo Prest SRL). The compressed two-month reporting window with consistently high activity suggests the use of automated attack tooling rather than isolated manual probing.
Active exploitation of SSH services represents a critical attack vector, as successful unauthorized access provides persistent server-level access to target infrastructure. Attackers leveraging non-standard port evasion techniques often combine credential brute-forcing with vulnerability exploitation to bypass basic authentication hardening. Once inside, threat actors can harvest sensitive data, deploy secondary payloads, or use the compromised host as a pivot point for lateral movement across connected networks.
Site operators should immediately block or rate-limit traffic from this address at the firewall level and audit SSH access logs for any matching connection attempts during the reported timeframe. Enforcing public-key authentication with password authentication disabled, configuring fail2ban to automatically block repeat offenders, and ensuring all SSH services run updated software versions will substantially reduce exposure to this class of threat. Ongoing monitoring of honeypot and community-sourced threat-intelligence feeds is recommended for identifying follow-up activity from related infrastructure.