Elevated Risk
IP 64.62.197.122 is a high-risk address operating from Hurricane Electric's AS6939 network in the United States, with 355 documented abuse reports and an 8/10 threat level indicating significant malicious activity primarily characterised by SSH brute-force intrusion attempts and exploited-host behaviour.
According to aggregated honeypot telemetry, this IP was first reported in August 2025 with activity continuing through June 2026, generating reports across 20 independent automated honeypot sensors. The dominant threat category is Hacking, accounting for 19 of the most recent reports, supplemented by isolated incidents classified as Exploited Host, SSH-specific activity, and IoT targeting. The 88% confidence score and 8/10 activity frequency demonstrate sustained, deliberate engagement with vulnerable services rather than opportunistic scanning. The detection data shows the address repeatedly attempting protocol manipulation and brute-force authentication against SSH services, suggesting systematic credential-guessing campaigns or participation in a broader botnet-driven assault infrastructure.
The reported activity pattern—combining SSH brute-force attempts with Suricata alerts indicating application-layer protocol exploitation—points to a dual-threat profile where the address both probes for weak credentials and potentially exploits misconfigured or outdated SSH implementations. An exploited-host classification alongside active hacking behaviour raises the possibility that this IP itself may be part of a compromised infrastructure being weaponised without its operator's knowledge, amplifying the risk to any exposed service encountering this traffic.
Site operators should block IP 64.62.197.122 at the network perimeter and implement fail2ban or equivalent rate-limiting rules to throttle repeated SSH authentication attempts. Hardening measures include enforcing key-based authentication exclusively, disabling root login over SSH, and moving default SSH ports. Monitoring inbound authentication logs for this address and similar source patterns will aid early detection. If the address appears to originate from a legitimate hosting provider, consider filing an abuse report with the network operator to potentially alert an unwitting system owner whose infrastructure may be compromised.