Extreme Threat
IP address 93.152.208.42 is a critical-risk address linked to sustained, high-volume hacking activity originating from Bulgarian network infrastructure. With a threat level of 10 out of 10 and 1,097 documented abuse reports logged between May and July 2026, this IP represents one of the most persistently malicious actors observed in recent public threat-intelligence data. The dominant activity recorded against this address consists of automated intrusion attempts and vulnerability probing targeting exposed services worldwide.
The 1,097 reports attributed to 93.152.208.42 reflect substantial sustained malicious traffic, with an activity frequency rating of 8 out of 10 indicating near-continuous scanning and connection attempts. All 20 of the most recent reports specifically categorize the activity as general hacking intrusion attempts, encompassing unauthorized access probing and exploitation of known vulnerabilities. The address operates within AS211486 under the administrative responsibility of Alferov Aleksey Aleksandrovich and geolocates to Bulgaria. The consistent volume of reports across the three-month observation window, combined with a 94% confidence score in threat attribution, provides strong empirical evidence of deliberate hostile infrastructure rather than opportunistic or transient compromise.
Hacking activity as recorded by automated honeypot sensors encompasses a broad spectrum of intrusion tradecraft, including port scanning, brute-force authentication attacks, exploitation of unpatched vulnerabilities, and probing for misconfigured services. For network operators with exposed SSH, RDP, web interfaces, or database ports, this sustained automated probing creates a direct pathway to unauthorized system access, credential theft, and potential lateral movement within internal networks. The volume and persistence of reports against 93.152.208.42 indicates infrastructure purpose-built for continuous exploitation attempts rather than opportunistic scanning.
Site operators should immediately block 93.152.208.42 at the network perimeter using firewall rules or intrusion prevention systems, and consider implementing geographic restrictions on access to administrative interfaces. Deploying tools such as fail2ban or configuring automated ban policies can mitigate repeated connection attempts in real time. Enforcing strong, unique credentials combined with multi-factor authentication on all exposed services significantly reduces the effectiveness of brute-force techniques. Maintaining comprehensive access logging with automated alerting enables rapid detection of probing patterns originating from this or similar addresses.