Extreme Threat
IP 64.188.91.244 is a high-risk address operated by H2nexus Ltd in Germany (ASN AS215730) that has generated 1,776 abuse reports from automated honeypot sensors since January 2026, with a dominant threat profile of hacking intrusion attempts and brute-force authentication attacks scoring a maximum 10/10 threat level.
The IP was first reported in January 2026 and last seen active in March 2026, with 20 distinct hacking-category incidents and a single brute-force event logged across automated honeypot detection systems. Despite the substantial aggregate report volume, the activity frequency metric of 0/10 suggests the address may currently be dormant following its operational window. Detection data reveals the IP was observed conducting VNC brute-force attempts against exposed services, alongside anomalous TCP stream behaviour flagged by network intrusion detection signatures. The network is routed through AS215730, a German hosting infrastructure operator, providing geographic and organizational context for the threat actor's footprint.
The dominant hacking activity represents systematic intrusion attempts targeting vulnerabilities and exposed services, with brute-force authentication attacks specifically attempting to guess credentials for remote access systems like VNC. The detected stream anomalies further indicate potential reconnaissance or exploitation of network-level weaknesses. With 1,776 accumulated reports, even at a 63% confidence score, this address demonstrates a persistent threat pattern that has been actively targeting systems across what appears to be a coordinated scanning and intrusion campaign.
Site operators should block this address at the network perimeter firewall, implement fail2ban or equivalent log-based intrusion prevention rules to auto-blacklist repeated authentication failures, enforce multi-factor authentication on all remote access services, and ensure VNC and similar protocols are not exposed to untrusted networks. Regular monitoring of authentication logs for this IP address and implementation of rate-limiting policies will further mitigate credential-guessing risks.