Notable Threat
IP 77.91.118.18 is a high-risk address originating from Russia, linked to sustained automated hacking activity including intrusion attempts and vulnerability exploitation, with 1,105 abuse reports filed against it over a concentrated three-month period in mid-2026.
Telemetry from automated honeypot sensors shows IP 77.91.118.18, allocated to INTEX ltd. in Russia (AS61436), generated all 1,105 reports through automated detection systems. The narrow timeframe between first reports in May 2026 and last reports in July 2026, combined with an activity frequency rating of 8/10, indicates a focused, intensive campaign rather than sporadic opportunistic scanning. The 94% confidence score reflects highly reliable detection with minimal ambiguity in the attack pattern classification.
The dominant threat category—hacking—encompasses a broad spectrum of intrusion activity including unauthorized access attempts, exploitation of vulnerable services, and automated exploitation toolkits. With over one thousand documented interactions and an 8/10 threat level, this IP has demonstrated repeated capability and intent to compromise exposed systems. Any publicly accessible service associated with this address faces material risk of credential compromise, data exfiltration, or further network penetration should initial access be achieved.
Defensive measures should include implementing automated abuse-management tools such as fail2ban to dynamically block repeated login failures, enforcing strong multi-factor authentication on all accessible services, maintaining rigorous patch management cycles, and monitoring adjacent IP ranges within AS61436 for related scanning activity. Organizations with direct exposure should review authentication logs for any connections originating from this address and consider a proactive block at the network perimeter.