Significant Threat
IP 182.72.60.162 is a high-risk address originating from India via AS9498 (Bharti Airtel Ltd.) that presents a significant threat due to sustained port-scanning activity, hacking reconnaissance, and SSH brute-force attempts, accumulating 158 abuse reports from automated honeypot sensors with a 93% confidence rating.
The IP was first reported in April 2026 and remained active throughout the same month, generating a notably high activity frequency score of 8 out of 10. Analysis of 20 independent honeypot sensor reports reveals a primary focus on port-scanning behavior (16 reports) and broader hacking activity (14 reports), alongside at least one confirmed SSH brute-force attempt. Network detection systems flagged this address for Ciscoasa port-scanning probes and Suricata stream-analysis anomalies involving malformed acknowledgment packets, patterns consistent with automated reconnaissance toolkits scanning for vulnerable services.
Port-scanning activity serves as initial reconnaissance, allowing threat actors to map exposed services and identify potential entry points before launching targeted exploitation attempts. The detected Suricata stream anomalies suggest the use of unconventional or deliberately corrupted packets to probe firewall and intrusion-prevention rule sets for evasion opportunities. The SSH brute-force component indicates the operator is actively attempting to compromise authentication mechanisms on exposed Secure Shell services, a common vector for gaining unauthorized server access and establishing persistent footholds within targeted networks.
Network defenders should block or rate-limit traffic from this address at the firewall level, enforce key-based SSH authentication while disabling password-based login and root access, and implement automated abuse-detection tools such as fail2ban to mitigate brute-force patterns. Monitoring for port-scan signatures and ensuring intrusion-detection systems are tuned to detect malformed TCP stream packets will reduce the effectiveness of the reconnaissance tactics observed from this source.