Severe Risk
IP 71.6.165.200 is a high-risk address with a critical threat rating of 10 out of 10, assessed with 81 percent confidence based on 195 total abuse reports submitted over approximately ten months between August 2025 and June 2026. The activity frequency of 6 out of 10 indicates persistent, repeated engagement with target systems, with the dominant threat category being general hacking activity, specifically including unauthorized SSH session establishment attempts detected by intrusion-prevention sensors.
The IP originates from the United States within CARINET's autonomous system AS10439, a network operator whose infrastructure appears to have been weaponized for malicious purposes despite its legitimate hosting environment. All 195 reports were generated by automated honeypot sensors configured to monitor and log unauthorized connection attempts, indicating this is not a case of isolated scanning but rather sustained, automated attack traffic. The detection timestamp data shows activity spanning from mid-2025 through mid-2026, demonstrating persistent threat actor behavior over an extended period rather than a brief opportunistic probe.
The dominant attack pattern involves repeated attempts to establish unauthorized SSH sessions on expected ports, a well-documented precursor to credential-based intrusion and lateral movement within targeted networks. This activity represents a concrete real-world risk to any exposed SSH services, as successful compromise could grant attackers persistent access, data exfiltration capability, or a pivot point for further network exploitation. The sustained volume of reports suggests this IP is likely part of an automated botnet or scanning infrastructure operating continuously against broad target ranges.
Site operators should implement immediate defensive measures including blocking or rate-limiting this IP at the network perimeter, enforcing strong authentication requirements for SSH access such as key-based authentication combined withfail2ban or similar tools to ban repeated offenders, disabling password-based authentication entirely where feasible, and monitoring logs for any similar connection patterns from adjacent address ranges. Regular review of honeypot and firewall logs will help identify if this threat actor's scanning has evolved or shifted tactics.