Severe Risk
IP address 152.200.217.230, originating from Colombian network operator COLOMBIA TELECOMUNICACIONES S.A. ESP BIC, is a critical-risk address currently under investigation for sustained SSH brute-force activity, with 206 abuse reports filed across 20 automated honeypot sensors over a four-month observation window between November 2025 and March 2026.
Security monitoring systems logged 22 distinct malicious events attributed to this address, predominantly SSH-related intrusion attempts alongside isolated general hacking probes and one indication that the host itself may have been compromised and weaponized. Detection confidence stands at 67 percent, reflecting the automated nature of the sensor network that generated these reports without direct attribution to a specific threat actor. The IP's reported activity frequency of 0/10 suggests the observations capture individual connection attempts rather than continuous sustained scanning, though the sheer volume of reports over five months indicates persistent, deliberate targeting rather than opportunistic random probing. The geographic concentration in Colombia and the ASN assignment to a major regional telecommunications provider points to either a residential compromised endpoint or infrastructure under adversarial control.
SSH brute-force attacks represent one of the most prevalent initial-access vectors in internet-facing infrastructure, with automated tooling capable of cycling through credential combinations at scale until valid access is achieved. When successful, such attacks grant adversaries foothold on servers, enabling data exfiltration, lateral movement through internal networks, cryptocurrency mining, or incorporation into botnets. The Suricata alerts noting active SSH sessions on expected ports suggest this address may have established connections to honeypot services, while the fail2ban violation logs confirm systematic authentication guessing. The single "Exploited Host" classification indicates security researchers have identified characteristics consistent with a system compromised without its legitimate operator's knowledge, meaning 152.200.217.230 itself could be an unwitting attack platform.