Severe Risk
IP 103.183.75.90 is a critical-risk address operated by PT Cloud Hosting Indonesia in Indonesia (AS136052) that has been linked to 827 SSH brute-force abuse reports detected by automated honeypot sensors between September 2025 and May 2026, representing a sustained and persistent threat to publicly accessible SSH services.
The IP has accumulated 827 total reports across 20 automated honeypot detection sources, with an activity frequency rated at 6 out of 10, indicating consistent engagement with target systems over an eight-month period. Fail2ban logs from monitored honeypot sensors documented multiple sshd brute-force violation events, including instances recording 25 violations and 10 violations respectively, confirming repeated automated attack attempts against SSH daemon services. With a threat level assessment of 10 out of 10 and a 75% confidence score, the evidence strongly supports that this address is actively involved in credential-guessing campaigns targeting SSH endpoints.
SSH brute-force attacks systematically attempt to gain unauthorized server access by rapidly cycling through username and password combinations, exploiting weak or default credentials. These automated attacks can precede data exfiltration, malware deployment, or integration into botnets for distributed denial-of-service operations. The volume and persistence of activity from IP 103.183.75.90 indicates a well-resourced operation capable of sustained scanning, posing significant risk to any exposed SSH service that relies on password-based authentication.
Administrators should immediately block IP 103.183.75.90 at the network perimeter firewall or through intrusion prevention systems, and implement fail2ban to dynamically ban addresses exhibiting brute-force behaviour. Transitioning to key-based authentication exclusively, disabling root login, and changing the default SSH port from 22 to a non-standard port will substantially reduce exposure. Continuous abuse-report monitoring and log analysis for authentication failures from this address will help identify any attempted reconnections.