High Risk
IP 64.62.197.152 is a high-risk address operating from the Hurricane Electric network (AS6939) in the United States, with a threat level of 8/10 and a 90% confidence score based on 405 total abuse reports. The dominant activity profile shows widespread hacking activity alongside evidence that this address may be running compromised host software, making it a significant concern for any exposed service.
Security monitoring systems detected this IP across 20 automated honeypot sensors between September 2025 and June 2026, indicating persistent and broadly distributed hostile probing. The high activity frequency score of 8/10 confirms consistent engagement with target infrastructure over this nine-month period. The underlying network belongs to Hurricane Electric, a major US bandwidth provider, which means traffic from this address likely carries the appearance of legitimate ISP-origin requests, potentially bypassing basic geo-based filters.
The reported hacking activity encompasses unauthorized access attempts, exploitation probing, and malware-related connections observed against honeypot sensors. An HTTP anomaly involving missing Host headers suggests the address is running automated scanning tools that fail to follow proper web protocol, a hallmark of mass vulnerability scanners or exploit frameworks. If this address is confirmed as an exploited host, it means a compromised system is being weaponized by threat actors without the owner's knowledge, allowing attacks to originate from what appears to be a legitimate US-based provider.
Network defenders should immediately block or aggressively rate-limit connections from 64.62.197.152 at the firewall or load balancer level. Implementing fail2ban or equivalent log-analysis tools can automatically ban repeat offenders matching this traffic signature. Organizations running publicly accessible SSH, HTTP, or other services should enforce strong authentication, limit login attempts, and ensure all software remains patched against known exploits. If this activity persists, consider filing an abuse report with Hurricane Electric referencing the confirmed malicious traffic patterns.