Severe Risk
IP 92.118.39.62 is a critical-risk address linked to sustained SSH brute-force attacks, with 12,749 abuse reports logged by automated honeypot sensors across a ten-month window. Originating from Unmanaged Ltd's AS47890 network in the United States, this IP exhibits a threat level rated 10 out of 10 and an activity frequency of 8 out of 10, reflecting persistent, high-volume malicious behavior that poses a direct intrusion risk to any exposed SSH service.
The data shows 20 distinct automated honeypot sensors across the community detecting this address between August 2025 and June 2026, with 12,749 total reports submitted. The dominant threat category is SSH activity, accounting for the majority of recent reports alongside significant Hacking-category detections and a single Exploited Host report. This combination of sheer report volume and category diversity indicates the address is engaged in both targeted credential attacks against SSH services and broader probing activity across multiple attack vectors. The "Exploited Host" classification suggests this IP may itself be a compromised system weaponized by threat actors, operating under the owner's knowledge.
SSH brute-force attacks attempt to gain unauthorized server access through automated password guessing against exposed daemons. The real-world risk is concrete: a successful credential compromise grants attackers direct shell access, enabling data theft, malware deployment, lateral network movement and the establishment of persistent footholds. Combined with the "Exploited Host" classification, this IP likely forms part of an automated attack infrastructure actively scanning and exploiting SSH vulnerabilities across internet-connected targets at scale.
Site operators with exposed SSH services should block 92.118.39.62 immediately at the firewall level and implement fail2ban or equivalent tools to auto-ban repeat offenders. Enforce key-based authentication exclusively, change the default SSH port, and disable root login. Keep all systems patched, enable intrusion detection monitoring, and review authentication logs for any matching connection patterns. If this IP originates from a hosting provider environment, consider submitting an abuse report to support@, as the single Exploited Host flag may indicate the system owner is unaware their infrastructure has been compromised.