High Risk
IP 152.32.189.128 is a high-risk address originating from Hong Kong that has been definitively linked to sustained hacking activity, with automated honeypot sensors logging over 2,000 separate reports documenting its malicious behavior across approximately ten months of continuous operation.
The address, registered to network operator ZEN-DPS under autonomous system AS62610, carries a threat level of 8 out of 10 with a confidence score of 89 percent based on reports gathered between September 2025 and July 2026. This volume of abuse reports is exceptionally high and indicates persistent automated engagement with target infrastructure rather than opportunistic scanning. All 2,036 reports were generated through automated honeypot sensors, and the activity frequency score of 8 out of 10 confirms ongoing, methodical attempts to compromise systems. The consistent detection across the reporting period suggests this IP address is actively maintained as part of malicious infrastructure.
Hacking activity encompasses diverse intrusion methodologies including vulnerability exploitation, exploitation of misconfigurations, and unauthorized access attempts against exposed services. The sustained nature of the reports — rather than brief opportunistic bursts — indicates the operator behind 152.32.189.128 is conducting systematic automated campaigns to identify and compromise vulnerable targets. This pattern poses significant risk to any exposed service, particularly those with unpatched software, default credentials, or publicly accessible management interfaces. The high report volume and extended operational timeframe suggest this address is successfully evading basic blocking mechanisms and continuing to probe new targets.
Site operators should immediately block or significantly rate-limit traffic from 152.32.189.128 at the network perimeter, ensuring the block extends across all services rather than selective ports. All exposed services should be audited for current security patches, with particular attention to remote access interfaces. Implement fail2ban or equivalent automated defense tools to dynamically block repeated connection attempts, and enforce strong authentication requirements including multi-factor authentication where available. Monitor logs for any connections originating from this address or adjacent IP ranges within AS62610 to identify potential follow-on reconnaissance or exploitation attempts.