Maximum Danger
IP 78.128.113.46 is a critical-risk Bulgarian address associated with sustained hacking activity, presenting a maximum threat level of 10 out of 10 based on 1067 total abuse reports gathered from automated honeypot detection systems between April and July 2026. The IP operates within AS209160, administered by Miti 2000 EOOD, a Bulgarian network entity, and demonstrates an activity frequency rating of 8 out of 10, indicating persistent and aggressive scanning behavior directed at internet-facing services. With a confidence score of 94 percent, the evidence base firmly establishes this address as a significant source of malicious traffic rather than incidental or misconfigured infrastructure.
The report corpus of 1067 filings originated exclusively from 20 distinct automated honeypot sensors over approximately four months, yielding an average detection rate exceeding 250 incidents per month. This sustained volume of reports from honeypot infrastructure specifically designed to attract and log intrusion attempts points to deliberate, automated targeting rather than opportunistic scanning. Network-layer telemetry captured via Suricata revealed an ICMP-based probe pattern consistent with network reconnaissance, where the target host communicated a administratively prohibited response, a technique commonly employed to map firewall rules and network topology before launching more targeted attacks.
The dominant threat classification for IP 78.128.113.46 is general hacking activity, a broad category encompassing unauthorized access attempts, vulnerability scanning, and exploitation of misconfigured or unpatched services exposed to the public internet. For organizations running accessible SSH, RDP, web applications, or database interfaces, an address with this threat profile represents a concrete risk of credential compromise, data exfiltration, or pivoting into internal networks. The sustained detection rate signals that automated attack tools are actively probing for entry points, making exposure to this IP functionally equivalent to constant hostile scanning of perimeter defenses.
Site operators should immediately block or implement aggressive rate-limiting on all ingress traffic from 78.128.113.46 at the network edge, deploy automated dynamic blocking tools such as fail2ban to counteract repeated authentication attempts, and enforce multi-factor authentication on all remote-access interfaces to render credential stuffing ineffective even if login attempts succeed. Regular security patching, continuous intrusion detection monitoring, and periodic review of access logs for originating requests from this address will further reduce the attack surface exposed to the techniques this IP routinely employs.