Maximum Danger
IP 64.188.91.248 is a high-risk address associated with VNC brute-force attacks and broader hacking activity, accumulating 2,232 abuse reports from automated honeypot sensors within a three-month window from January to March 2026, making it a clear candidate for blocking at the network perimeter.
The address operates through AS215730 under H2nexus Ltd and is geolocated in Germany, a jurisdiction that does not inherently suggest malicious hosting; however, the concentration of 22 distinct threat events across 20 separate honeypot detection points indicates deliberate, systematic scanning behaviour rather than incidental traffic. The dominant detection signature, flagged by Suricata as a broken-ack stream anomaly during a VNC brute-force attempt, aligns precisely with the 20 hacking-category reports and 2 brute-force-specific reports submitted during this period.
VNC brute-force activity represents a concrete and immediate threat to any exposed remote desktop services. Attackers using this method systematically iterate authentication credentials against VNC servers, which frequently lack adequate rate-limiting or lockout protections. Successful compromise grants direct graphical access to internal systems, enabling lateral movement, data exfiltration or deployment of follow-on malware. The broken-ack stream signature suggests the attacking client is deliberately fragmenting or mangling TCP handshake packets to evade basic detection or exploit stateful-inspection gaps.
Site operators with publicly accessible VNC or similar remote-access services should immediately block 64.188.91.248 at the firewall or edge device, implement strict port-access controls on TCP 5900-range services, and enforce strong, non-default credentials alongside multi-factor authentication where feasible. Deploying fail2ban or equivalent log-analysis tools to automatically ban sources exhibiting brute-force patterns will reduce long-term exposure. Regular review of authentication logs for source-IP concentration from this address, combined with intrusion-detection alerting, provides essential situational awareness.