Severe Risk
IP 45.198.224.46 is a critical-risk address operated by Vpsvault.host Ltd in the United States, associated with an extraordinarily high volume of automated attack activity spanning May to July 2026. With 1,368 total abuse reports and a 94% confidence score, this IP has been flagged across 20 automated honeypot sensors as an active source of SSH brute-force intrusion attempts and broader hacking activity against exposed services. The threat level of 10/10 and activity frequency of 8/10 underscore the severity and persistence of the malicious behaviour originating from this address.
The overwhelming majority of reports — 19 for SSH activity and 19 for general hacking — point to sustained credential-guessing campaigns targeting Secure Shell services, while a single report of exploited-host classification suggests this IP may itself be a compromised system repurposed as an automated attack platform without its owner's knowledge. Detection signatures, including Suricata alerts for SSH sessions on expected brute-force ports, confirm that this address is systematically probing remote servers for weak credentials or unpatched SSH vulnerabilities. The concentration of reports across multiple independent honeypot sensors across a compressed three-month window indicates a deliberate, coordinated scanning and exploitation operation rather than opportunistic noise.
SSH brute-force attacks represent one of the most common initial-access vectors in real-world intrusions; an attacker using this IP is systematically testing username-and-password combinations against publicly accessible servers, hoping to gain unauthorized shell access. If successful, the attacker could deploy backdoors, exfiltrate data, or pivot deeper into a network. The additional exploited-host designation raises the possibility that the owner of 45.198.224.46 is unaware their infrastructure is being weaponised, which does not diminish the risk to potential victims. Any service with port 22 exposed to this IP faces repeated, automated credential-stuffing attempts that dramatically increase the probability of compromise over time.
Site operators should block 45.198.224.46 at the firewall or network edge immediately and monitor logs for any matching inbound connection attempts. Switching SSH access to non-default ports, enforcing key-based authentication in place of passwords, and deploying tools such as fail2ban to automatically ban repeat offenders will substantially reduce exposure. Keeping SSH daemons fully patched, disabling root login, and implementing aggressive account-lockout policies add additional layers of defence against the techniques detected from this source. Organizations that receive connections from this IP should consider notifying the hosting provider, as the exploited-host classification indicates the address itself may require remediation.