Critical Threat
IP 77.91.118.50 is a critical-risk address operated by INTEX ltd. in Russia, AS61436, that has been linked to sustained hacking activity with 1,100 abuse reports submitted through automated honeypot sensors over a concentrated three-month window between May and July 2026.
The volume and consistency of reports from these honeypot sensors indicate persistent, automated intrusion activity originating from this IP address. With a threat level rated at 10 out of 10 and an activity frequency score of 8 out of 10, this address demonstrates a high rate of ongoing malicious connection attempts. The 94% confidence score and 1,100 total reports from 20 distinct honeypot sources confirm this is not an isolated incident or misconfiguration but rather sustained hostile reconnaissance and exploitation activity targeting exposed services across the internet.
General hacking activity encompasses a broad range of intrusion techniques, including automated scanning for vulnerable services, exploitation of known software vulnerabilities, brute-force authentication attacks, and attempts to establish unauthorized remote access. For organizations running exposed SSH, Telnet, HTTP APIs, or other network-accessible services, this type of sustained probing represents a concrete and immediate risk of unauthorized system access, data exfiltration, or lateral movement within a compromised network.
Operators should implement immediate blocking or aggressive rate-limiting for this address at the network perimeter firewall. Enabling automated dynamic blocklists such as fail2ban can detect and respond to repeated connection patterns characteristic of the observed activity. All exposed services should enforce strong, unique credentials and certificate-based authentication where possible. Continuous monitoring of inbound connection logs from unknown sources is strongly advised to identify any successful intrusion attempts that may bypass initial defensive layers.