Extreme Threat
IP 45.148.10.121 is a high-risk Dutch address with a threat level of 10/10 that has accumulated 2,420 total abuse reports from automated honeypot sensors, with activity most recently detected in June 2026. Operated by Techoff Srv Limited under ASN AS48090 in the Netherlands, this IP presents a severe and ongoing risk primarily driven by SSH brute-force attacks and broader hacking activity against exposed services.
The volume of reporting is substantial — 2,420 total reports sourced from 20 distinct automated honeypot sensors is a clear indicator of persistent, automated scanning behaviour rather than a one-off probe. The activity frequency score of 8/10 and the confidence score of 82% confirm that multiple independent detection points have logged this IP's behaviour over a consistent timeframe spanning from December 2025 through June 2026. The dominant reported categories are Hacking (19 reports), SSH (14 reports), and Exploited Host (1 report), with specific Suricata alerts documenting active SSH sessions on expected ports, SSH brute-force attempts, and at least one instance classified as an exploited SSH endpoint. The presence of both brute-force patterns and an exploited-host classification suggests this address may be actively running an attack campaign against SSH services while simultaneously showing signs of being used as a launchpad for additional intrusion activity.
SSH brute-force attacks represent one of the most common initial-access vectors used against publicly reachable Linux and network devices. An attacker operating from IP 45.148.10.121 systematically attempts to authenticate against SSH services by cycling through common username and password combinations, exploiting weak or default credentials. Even a single successful authentication grants an attacker a foothold on the target system, potentially enabling data exfiltration, lateral movement within a network, or the deployment of secondary payloads such as cryptominers or ransomware. The inclusion of an Exploited Host flag indicates that infrastructure associated with this IP has previously been leveraged for hostile purposes, reinforcing that blocking this address is the appropriate immediate response.