Elevated Risk
IP 152.32.172.108, registered in Hong Kong and operated through ASN AS62610 (ZEN-DPS), is a high-risk threat actor with a threat level of 8/10 and a confidence score of 94%, based on 1,486 total abuse reports spanning from September 2025 to June 2026. The address demonstrates persistent, high-frequency malicious activity with an activity frequency rating of 8/10, indicating consistent engagement in hostile operations over a sustained nine-month period.
The IP has been flagged exclusively for hacking activity across all 20 of its most recent reports, with detection sourced entirely from automated honeypot sensors monitoring exposed network entry points. This volume of community and sensor reports over an extended timeframe signals a deliberate, systematic scanning and intrusion campaign rather than opportunistic or incidental traffic. The ZEN-DPS network in Hong Kong has hosted this actor throughout its entire observed operational window, suggesting either deliberate allocation for malicious use or insufficient abuse management by the network operator.
Hacking activity at this scale typically involves repeated attempts to exploit vulnerable services, brute-force authentication mechanisms, or probe for misconfigurations that could grant unauthorized system access. The sustained frequency of reports indicates the operator behind this IP is actively cycling through targets, increasing the probability that any exposed service accepting connections from this address will encounter credential-guessing, service enumeration, or vulnerability exploitation attempts. Real-world risk includes compromised accounts, data exfiltration, or pivot points for deeper network intrusion.
Site operators should block IP 152.32.172.108 at the firewall or load-balancer level given its confirmed malicious history. Implement fail2ban, crowdsec, or similar dynamic denial-of-service tools to automatically ban addresses generating repeated suspicious patterns. Enforce strong authentication on all accessible services, apply multi-factor authentication where feasible, and ensure systems are promptly patched against known vulnerabilities. Continuous monitoring and log analysis for connections originating from this address will help identify any successful compromise attempts early.