High Risk
IP 64.62.156.80 is a high-risk address associated with active hacking activity, displaying sustained threat behavior over approximately ten months with a substantial volume of abuse reports. The address, operating through Hurricane Electric's AS6939 network in the United States, has accumulated 808 total reports with 20 recent reports specifically categorizing the activity as hacking attempts. With a threat level rating of 8 out of 10 and an activity frequency score of 8 out of 10, this IP demonstrates persistent malicious intent that warrants immediate defensive attention from any organization with exposed network services.
Analysis of available data shows 808 abuse reports attributed to 64.62.156.80, with the most recent documented activity occurring in June 2026. All 20 most recent reports uniformly identify the threat category as hacking activity, detected exclusively through automated honeypot sensors. Security sensors flagged "attack connection" patterns alongside Suricata alerts indicating application-layer protocol mismatch conditions in both communication directions, suggesting the source is transmitting unexpected or malformed protocol communications typical of automated scanning and vulnerability probing tools.
The dominant hacking classification for this IP encompasses unauthorized access attempts, exploitation of vulnerabilities, and general intrusion activity. The detected protocol mismatch conditions indicate the source is probing for services that may be misconfigured, outdated, or vulnerable to known exploits. Such behavior is characteristic of infrastructure used to mass-scan the internet for exploitable entry points, and while individual attempts may be generic, the sustained activity frequency confirms ongoing hostile reconnaissance targeting potentially vulnerable systems.
Organizations with internet-facing services should implement blocking or rate-limiting measures for this source at the network perimeter, ensure all exposed services are current on patches and properly hardened against common exploit vectors, and consider deploying automated threat-response tools such as fail2ban to dynamically block repeated connection attempts. Maintaining monitoring for any successful connections originating from this address and reporting the activity to Hurricane Electric's abuse handling team can further contribute to collective defense efforts within the AS6939 network.