Critical Threat
IP address 167.94.146.58 is a critical-risk address that has generated 412 abuse reports from automated honeypot sensors since August 2025, with activity most recently observed in June 2026, making it one of the most prolific sources of malicious traffic in recent threat intelligence. Operating from AS398705 under the network designation CENSYS-ARIN-02 and physically located in the United States, this IP has achieved a threat level of 10 out of 10 and a confidence score of 94 percent, indicating an exceptionally reliable assessment of its dangerous nature. The volume of reports and near-constant activity frequency score of 8 out of 10 confirm that this is not an isolated incident but rather sustained, deliberate hostile operations targeting infrastructure across the internet.
The dominant threat category associated with 167.94.146.58 is general hacking activity, supported by 19 specific category reports alongside one additional report of exploited host behavior, suggesting this address functions both as an active attack platform and potentially as a compromised system itself being weaponized without its operator's knowledge. Detection mechanisms recorded Suricata alerts flagging SSH sessions established on expected ports, alongside general malware and exploit activity patterns consistent with unauthorized access attempts. The 20 distinct automated honeypot sensors that contributed reports span multiple detection points, confirming that this activity is geographically and topologically widespread rather than the output of a single biased observation point.
The concrete risk posed by this address centers on its demonstrated capability and intent to compromise exposed services through sustained intrusion attempts and exploitation techniques. An SSH session in progress on expected ports indicates active credential-based attacks or session hijacking attempts against services that administrators may believe are safely exposed. The combination of general hacking behavior with exploited host classification means traffic originating from 167.94.146.58 could represent either a malicious actor directly probing for vulnerabilities or a previously compromised endpoint now participating in a broader attack campaign. Any exposed service encountering this traffic faces immediate risk of unauthorized access, data exfiltration, or further network compromise.