High Risk
IP 92.63.197.79 is a high-risk address originating from Ukraine that has been linked to sustained port-scanning reconnaissance activity, with automated honeypot sensors and community reports logging 1743 total abuse reports since March 2026. The IP operates within AS211736 (FOP Dmytro Nedilskyi) and carries an 8/10 threat level with 91% confidence, indicating a reliable attribution of malicious intent. The sustained volume and frequency of reports over a three-month window suggest persistent automated scanning rather than opportunistic or transient probing.
Detection data shows this address consistently targeting exposed services with CiscoASA port scan patterns, a technique designed to identify open ports and available attack surfaces on network perimeters. The 20 most recent reports all cite port scanning as the dominant threat category, with honeypot sensors across multiple networks capturing the reconnaissance behavior. The March-to-June 2026 reporting window demonstrates that this activity is not isolated but represents an ongoing campaign, with the IP maintaining an 8/10 activity frequency throughout the period. The geographic origin in Ukraine and the specific targeting of CiscoASA appliances suggest the operator may be conducting systematic vulnerability assessment at scale.
Port scanning constitutes the initial reconnaissance phase of most targeted attacks, mapping exposed services that could later be exploited through brute-force attempts, credential stuffing or exploitation of known vulnerabilities. A CiscoASA device identified as open or misconfigured during this scanning phase could become the entry point for subsequent intrusion attempts, data exfiltration or lateral movement within a network. The volume of reports associated with this IP indicates it has been actively probing numerous organizations, increasing the statistical likelihood that at least some targets were found to be vulnerable or misconfigured.
Network defenders should treat this IP as a confirmed threat source and implement immediate blocking at the firewall or edge-device level. Exposed services should be minimized to essential ports only, with strict ingress and egress filtering applied according to least-privilege principles. Organizations running CiscoASA appliances should verify current firmware patches and confirm that management interfaces are not internet-facing. Stateful firewall rules with rate-limiting on inbound connections, combined with detection tools such as fail2ban or equivalent log-analysis frameworks, will further reduce the effectiveness of similar scanning campaigns targeting your infrastructure.