Severe Risk
IP 152.32.189.121 is a critical-risk address operating from the Hong Kong network AS62610 (ZEN-DPS) that has generated 2,011 abuse reports across 20 automated honeypot sensors over approximately ten months of sustained malicious activity. With a threat level of 10/10 and an activity frequency rating of 8/10, this IP represents one of the most prolific and dangerous scanning and intrusion entities currently active in public threat intelligence feeds.
The detection data reveals a sustained campaign spanning September 2025 through July 2026, with a confidence score of 89% indicating highly reliable attribution. The dominant threat category is general hacking activity encompassing intrusion attempts and exploitation of vulnerabilities, supplemented by IoT and ICS-targeted operations. Report sources consistently identify "attack connection" patterns alongside IoT/ICS targeting behavior, suggesting this actor systematically probes both traditional server infrastructure and operational technology environments for weaknesses. The volume of reports combined with the multi-sensor detection footprint confirms this is not isolated scanning but persistent, automated reconnaissance and exploitation activity.
The dual threat profile of this IP poses distinct risks to exposed organizations. Hacking activity implies attempts to brute-force credentials, exploit known vulnerabilities, or deliver payloads through compromised services. The IoT-targeted component specifically targets smart devices, routers, cameras, and industrial control systems that frequently ship with weak default credentials, unpatched firmware, and misconfigured network services. An organization with inadequately segmented IoT deployments could find these devices leveraged as entry points for lateral movement into core enterprise networks, or recruited into botnets for further coordinated attacks.
Site operators should immediately block or heavily rate-limit traffic from this IP at the network perimeter firewall, and implement automated blocking tools such as fail2ban to handle similar future threats without manual intervention. All internet-facing services should enforce strong, unique credentials and multi-factor authentication to resist credential-based attacks. IoT and ICS devices require network segmentation from critical systems, mandatory firmware updates, and disabled universal plug-and-play features. Continuous traffic monitoring for connection attempts from this address and similar suspicious patterns will help identify any successful intrusions before significant damage occurs.