Severe Risk
IP 152.32.189.121 is a critical-risk address associated with sustained, high-volume hacking activity, having accumulated 2,383 abuse reports from automated honeypot sensors between September 2025 and August 2026, with the overwhelming majority classified under general intrusion and unauthorized access attempts. The threat level of 10/10 and an activity frequency rating of 8/10 confirm this as one of the most persistently malicious IPs observed in recent network telemetry, warranting immediate blocking at the perimeter level by any exposed infrastructure.
The detection profile for 152.32.189.121 draws from 20 distinct automated honeypot sensors reporting connection-based probing and intrusion patterns, producing a confidence score of 86% that this address is operating as an active threat actor. Geolocated to Hong Kong and routed through AS62610 under the operator designation ZEN-DPS, the IP demonstrates a deliberate, sustained campaign spanning approximately 11 months without interruption. The sheer volume of reports relative to the detection window indicates systematic, automated scanning behaviour rather than opportunistic or short-lived activity, placing it squarely in the category of infrastructure used for persistent vulnerability enumeration and exploitation preparation.
Hacking activity at this scale typically involves repeated attempts to exploit misconfigured services, brute-force authentication interfaces, or known software vulnerabilities across exposed endpoints. The sustained nature of the reports suggests that 152.32.189.121 is part of an automated toolkit used to systematically probe networks for entry points, with the "attack connection" pattern indicating repeated handshake and credential-fetching behaviour against services such as SSH, Telnet, or web-based management portals. For any organisation running exposed services, this IP represents a concrete risk of unauthorized access, data exfiltration, or lateral movement into internal systems if initial compromise succeeds.
Site operators should block 152.32.189.121 at the firewall or network edge immediately, and consider implementing rate-limiting on authentication endpoints to reduce the effectiveness of credential-guessing campaigns. Deploying intrusion detection signatures tuned to the observed connection patterns and using tools such as fail2ban to dynamically update blocklists will further harden defences. Regular audit of exposed services, enforcement of strong multi-factor authentication, and monitoring of authentication logs for patterns consistent with this IP's activity will help identify any successful compromise attempts originating from this address.