Maximum Danger
IP 195.178.110.30 is a high-risk address operated by Techoff Srv Limited in Bulgaria (ASN AS48090) that has generated 27,045 abuse reports through automated honeypot sensors, indicating sustained and aggressive SSH brute-force activity against exposed authentication endpoints worldwide.
With a threat level of 10 out of 10 and an activity frequency rating of 8 out of 10, this IP demonstrates persistent hostile behavior. The detection network recorded 20 separate honeypot sensor confirmations across recent reporting periods, with the majority of threats classified as SSH attacks (20 reports), general hacking activity (15 reports), and brute-force authentication attempts (6 reports). Observed attack patterns include repeated SSH brute-force sequences and automated authentication failures triggering standard defensive response mechanisms. The first reports emerged in October 2025, with continued activity logged through June 2026, suggesting an extended campaign rather than isolated probing.
SSH brute-force attacks systematically attempt to crack authentication credentials by iterating through username and password combinations against exposed Secure Shell services. The concrete risk involves unauthorized server access, data exfiltration, lateral network movement, and potential deployment of persistent backdoors or cryptocurrency mining utilities. Even failed attempts consume server resources and generate security-noise that can obscure genuine incidents. Organizations running publicly accessible SSH services without robust credential hardening remain primary targets for this attack methodology.
Site operators should implement key-based authentication exclusively for SSH access, change the default listening port to reduce automated targeting, and deploy authentication rate-limiting mechanisms such as fail2ban to automatically block sources after repeated failures. Disabling direct root login, enforcing strong password policies with account lockout thresholds, and enabling multi-factor authentication provide layered defense against credential-guessing campaigns. Regular monitoring of authentication logs for unusual patterns from IP 195.178.110.30 and similar addresses is strongly recommended.