Elevated Risk
IP address 185.136.15.110, allocated to a network operated by Vlad Cojuhari under ASN AS205997 in Kazakhstan, presents a high-risk threat profile with a threat level of 8/10 and a confidence score of 91 percent based on more than 1,000 total abuse reports submitted through automated honeypot sensors. The address was first reported in July 2026 and remains active as of August 2026, indicating sustained malicious behavior over a multi-month window. The dominant threat category driving these reports is port scanning activity, with a specific focus on CiscoASA firewall appliances detected in recent probe patterns.
The sheer volume of reports — 1,000 over approximately two months — far exceeds typical baseline noise observed across most IP addresses in global threat-feeds, placing this address in the upper tier of reported sources. The activity frequency score of 8/10 confirms that the scanning behavior is not isolated or sporadic but represents a persistent, automated campaign. All 20 most recent reports originate exclusively from automated honeypot sensors, which are designed to mimic vulnerable services and capture inbound reconnaissance traffic with high fidelity. The geographic assignment to Kazakhstan and the association with a named individual network operator provides network-level context that distinguishes this IP from dynamically allocated or anonymized infrastructure commonly used in short-lived attack campaigns.
Port scanning constitutes the initial reconnaissance phase of most targeted attacks. By enumerating open services and accessible ports on exposed systems, an attacker maps the attack surface before selecting specific vulnerabilities to exploit. The documented focus on CiscoASA probes is particularly concerning because these devices are critical network-edge appliances; successful identification of an unpatched or misconfigured CiscoASA instance could enable remote-code-execution or firewall-bypass attacks with severe consequences for the target organization. An IP maintaining this level of persistent, high-frequency scanning activity over months effectively functions as an active reconnaissance platform, elevating risk for any organization with exposed CiscoASA or similarly instrumented perimeter devices.
Site operators should immediately block 185.136.15.110 at the network perimeter firewall and monitor logs for any correlated access attempts from adjacent IP ranges within AS205997. Implementing strict egress and ingress filtering will limit the effectiveness of any port-probe findings. Authentication hardening — including enforcement of strong credentials, key-based authentication where applicable, and tools such as fail2ban to automatically block repeated probe attempts — substantially reduces exposure to follow-on attacks that this reconnaissance could enable. Continuous monitoring of honeypot and network telemetry feeds is recommended to detect any shift in the IP's tactics beyond port scanning.