Severe Risk
IP 152.32.189.121 is a high-risk address operating from Hong Kong through ASN AS62610 (ZEN-DPS) that has accumulated 1,518 abuse reports across automated honeypot sensors with a threat level rating of 10/10 and a confidence score of 94%, indicating near-certain malicious intent associated with sustained hacking activity over approximately nine months of continuous operation.
The IP was first reported in September 2025 with its most recent activity logged in June 2026, demonstrating persistent engagement in hostile reconnaissance and intrusion attempts against exposed network services during this period. All 20 recent threat-category reports classify the activity as general hacking operations encompassing exploitation attempts and unauthorized access probes. The activity frequency rating of 8/10 confirms this is not opportunistic or sporadic scanning but rather sustained, methodical targeting of vulnerable systems by this single source address operating through a network associated with dynamic packet-switched infrastructure.
Hacking activity at this volume and persistence represents a concrete risk to any exposed service running outdated software, misconfigured authentication mechanisms, or known-vulnerable applications. The sustained nature of the attacks combined with the high report volume suggests automated tooling capable of enumerating and exploiting a broad range of vulnerabilities across numerous target environments. Organizations with internet-facing services that fail to implement proper hardening measures face significant exposure to credential compromise, data exfiltration, or secondary infection through this single threat vector.
Defensive measures should include immediate blocking of this IP at the network perimeter firewall or through intrusion prevention systems, implementation of fail2ban or similar dynamic firewall tools to automatically ban repeat offenders, enforcement of strong multi-factor authentication on all remote access services, and regular patching cycles to eliminate known vulnerabilities that this actor likely attempts to exploit. Continuous monitoring of authentication logs for failed login patterns originating from this address range will further reduce exposure risk.