Severe Risk
IP 93.152.208.38 is a high-risk address assessed at a critical threat level of 10 out of 10, linked to active hacking activity detected across automated honeypot sensors over a concentrated two-month window from May to July 2026. With 1,085 total reports and a confidence score of 94 percent, this Bulgarian IP presents a severe and ongoing risk to any exposed network services. The activity frequency rating of 8 out of 10 indicates sustained, aggressive behavior rather than isolated probes, making this address particularly dangerous for systems with open attack surfaces.
The aggregate report volume of 1,085 abuse reports reflects significant hostile engagement directed at honeypot infrastructure, suggesting the IP has been systematically scanning and attempting intrusions against targeted endpoints. All 20 of the most recent threat-category reports classify the activity as general hacking, encompassing vulnerability exploitation attempts and unauthorized access probing. Operating from AS211486 under the network operator Alferov Aleksey Aleksandrovich, this address originates from Bulgaria and has demonstrated persistent offending behavior across the full May–July 2026 reporting period, with no indication of voluntary cessation.
Hacking activity of this intensity typically involves automated tooling that systematically enumerates exposed services, tests for known vulnerabilities, and attempts to breach authentication mechanisms. The sheer volume of reports indicates the address is part of an active campaign, likely operating as part of a botnet or automated scanning infrastructure. Organizations with SSH, Telnet, or web-facing services without adequate hardening face substantial risk of credential compromise, data exfiltration, or server takeover if this IP is not blocked at the network perimeter.
Network administrators should immediately block 93.152.208.38 at the firewall or edge device to eliminate inbound threat vectors. Implementing fail2ban or equivalent dynamic firewall rules can automate blocking of repeated connection attempts from abusive sources. Enforcing strong, unique credentials and disabling password-based authentication in favor of key-based access will substantially reduce the effectiveness of any intrusion attempt. Regular patching, disabling unused services, and deploying intrusion-detection monitoring will further harden environments against the exploitation patterns associated with addresses in this threat profile.