Critical Threat
IP 91.237.163.113 is a high-risk address originating from Russia and operated by Systematica LLC (ASN AS211724) that has been linked to 561 reported incidents of malicious activity, predominantly SSH brute-force attacks targeting exposed server login interfaces. This IP address presents a severe threat to any internet-facing systems with open SSH ports, as the volume and consistency of reports indicate persistent, automated intrusion attempts rather than isolated scanning. Despite a relatively low recent activity frequency score, the historical report count and confirmed threat classifications establish this address as a dangerous source of credential-based attack traffic that security teams should actively block or heavily restrict.
The abuse reports for IP 91.237.163.113 were generated by twenty distinct automated honeypot sensors, indicating that the scanning and attack infrastructure associated with this address is both distributed and well-instrumented. Reports span from October 2025 through March 2026, with the dominant threat categories being Hacking activity (18 recent reports) and SSH-specific attacks (11 recent reports). The honeypot logs consistently document SSH brute-force attempts, with multiple failed authentication events logged by defensive tools, confirming systematic attempts to guess SSH credentials rather than opportunistic port scanning. The 66% confidence score reflects that while the hostile intent is clear, attribution to a definitive malicious actor remains partially uncertain.
SSH brute-force attacks represent one of the most common and effective methods threat actors use to gain unauthorized access to Linux servers and network infrastructure. Attackers deploy automated tools that cycle through username and password combinations at high speed, exploiting weak or default credentials to breach systems. Once inside, attackers can deploy backdoors, exfiltrate data, pivot to internal networks, or enlist compromised servers into botnets. For organizations with exposed SSH services, a single successful brute-force attempt can lead to complete server compromise, making this threat category particularly severe and the rationale behind the maximum threat level assigned to IP 91.237.163.113.