Substantial Risk
IP 80.94.92.167 is a maximum-threat-level address originating from Romania (ASN AS47890, operated by Unmanaged Ltd) that has accumulated 5,560 total abuse reports, primarily linked to SSH brute-force intrusion attempts detected by automated honeypot sensors.
Threat-intelligence databases show this IP was first reported in November 2025 and most recently in January 2026, with 20 separate honeypot sensors flagging the address across that period. The 5,560 total reports represent a substantial volume, though the confidence score of 59% indicates moderate uncertainty in attributing all reported activity definitively to this single source. Recent reports show 14 hacking-category events and 6 specifically categorized as SSH attacks, confirming sustained focus on credential-based access attacks rather than other threat vectors. The activity frequency metric of 0/10 suggests no new detections within the most recent reporting window, which may indicate the IP has ceased operations against monitored sensors or shifted tactics.
SSH brute-force attacks represent one of the most common initial-access vectors facing internet-exposed servers, where adversaries systematically attempt username and password combinations to authenticate over the Secure Shell protocol. Successful compromise of an SSH server grants attackers persistent command-line access, enabling data exfiltration, malware deployment, lateral movement through internal networks, or recruitment into botnets. The scale of 5,560 reports against this single address demonstrates an automated, high-volume campaign likely conducted by botnets or commercial attack toolkits rather than manual intrusion attempts.
Site operators exposing SSH services should immediately enforce key-based authentication, change the default port from 22, disable root login, and implement fail2ban or similar dynamic blocking tools to automatically reject repeated authentication failures. Continuous monitoring of authentication logs and network-level rate limiting provide additional defensive layers against the credential-guessing techniques associated with this threat profile.