Notable Threat
IP 92.63.197.23 is a high-risk address associated with port-scanning reconnaissance activity, originating from Ukrainian infrastructure under ASN AS211736 operated by FOP Dmytro Nedilskyi. With a threat level of 8 out of 10 and 2,509 total abuse reports filed against it, this IP represents a persistent scanning threat tracked by automated honeypot sensors over approximately eight months between August 2025 and April 2026. The confidence score of 73% reflects solid evidentiary backing for the attributed malicious behavior despite a notably low recent activity frequency score of 0 out of 10, suggesting that while the scanning campaigns have diminished in the immediate period, the historical record firmly establishes this address as a source of hostile network reconnaissance.
The detection data reveals that all 20 most recent reports from automated honeypot sensors uniformly categorize the activity as port-scanning behavior, specifically CiscoASA probe patterns targeting firewall and security appliance configurations. The sheer volume of accumulated reports—2,509 across the observation window—indicates sustained, repeated scanning operations rather than isolated probes. The geographic origin in Ukraine and the network registration under an individual operator do not by themselves indicate malicious intent, but the concentrated focus on security appliance identification aligns with pre-attack reconnaissance patterns commonly associated with threat actors preparing for further exploitation attempts against exposed network perimeters.
Port scanning constitutes the foundational reconnaissance phase of most targeted cyberattacks, allowing adversaries to map exposed services, identify potentially vulnerable configurations, and select targets for subsequent intrusion attempts. When specifically probing CiscoASA security appliances, threat actors seek to enumerate firewall rule sets, identify outdated firmware versions with known exploits, or discover misconfigured VPN endpoints that could serve as initial access vectors. The 73% confidence attribution suggests that while automated systems have high certainty this IP is performing reconnaissance, some uncertainty remains regarding the ultimate intent or affiliation of the operator behind the scanning activity.