Severe Risk
IP 39.144.91.193 is a critical-risk address originating from Hebei Mobile Communication Company Limited's network in China, with a threat level rated 10 out of 10 based on 335 total abuse reports and a 73% confidence score that the activity is malicious. The IP has been flagged exclusively through automated honeypot sensors, with recent reports in November 2025 categorizing the activity as general hacking attempts including intrusion and unauthorized access efforts.
Analysis of the available data reveals a substantial volume of reports with a moderate-high confidence rating. The 335 total reports against this single IP address indicate persistent attention from automated detection systems, while the 20 most recent reports all align under the Hacking threat category. Detection was performed entirely through automated honeypot sensors, confirming the IP's consistent probing behavior against vulnerable services. The network operator, Hebei Mobile Communication Company Limited (AS24547), operates out of China, and the IP was first and last reported within the November 2025 timeframe, suggesting concentrated activity during that period.
The dominant Hacking classification encompasses a broad spectrum of intrusion activities, including vulnerability exploitation attempts, credential-based attacks, and unauthorized access probes against exposed services. Despite the low activity frequency score of 0 out of 10, the sheer volume of historical reports demonstrates that IP 39.144.91.193 has been systematically targeting network resources. Real-world risk includes potential compromise of unpatched services, brute-force authentication bypass, and exploitation of known vulnerabilities in internet-facing applications, which could lead to data breaches or system takeover.
Defensive measures should include immediate blocking or rate-limiting of traffic from this IP at the network perimeter firewall, implementation of fail2ban or similar log-based intrusion prevention tools to automatically ban repeat offenders, enforcement of strong multi-factor authentication on all accessible services, and regular patching cycles for internet-facing systems to reduce exploitable attack surface. Continuous monitoring of authentication logs for sources matching this IP's activity patterns is strongly advised.