Maximum Danger
IP 94.156.152.18 is a high-risk address operating from Bulgaria (AS214209, Internet Magnate (Pty) Ltd) that has generated 302 abuse reports with a 94% confidence score, making it one of the most actively threatening IPs in recent aggregations. The address exhibits an activity frequency rating of 8 out of 10, indicating sustained, repeated offensive operations rather than isolated probes. Automated honeypot sensors across 20 distinct sources have consistently flagged this IP for concurrent hacking, SSH brute-force activity, web application probing, and evidence of successfully exploited SSH sessions. The concentration of report categories — with hacking and SSH threats accounting for the vast majority of 302 incidents — paints a clear picture of an attacker focused on gaining unauthorized remote server access through credential brute-forcing and subsequent exploitation.
The temporal data shows all activity clustered within a single reporting window of May 2026, suggesting a concentrated, deliberate campaign rather than opportunistic scanning. The honeypot telemetry specifically captured Suricata alerts indicating SSH sessions established on expected ports, combined with brute-force attempt signatures. This pattern is consistent with automated tooling designed to systematically test default and weak SSH credentials across internet-facing servers. Additionally, the single "Exploited Host" classification indicates that at least one target was successfully compromised, demonstrating that this IP has moved beyond reconnaissance into active exploitation.
The dominant threat vectors represent distinct but complementary risks. SSH brute-force attacks target any exposed port 22 (or non-standard ports running SSH), attempting to guess credentials until access is granted — a volume-based approach that succeeds against poorly configured or weak-password systems. The web application probing component suggests simultaneous scanning for web-facing vulnerabilities such as injection flaws or misconfigurations. When combined with confirmed exploitation success, this IP functions as a general-purpose intrusion tool capable of both initial access and post-compromise activity, posing a direct threat to any organization with exposed SSH services or unhardened web applications.