Significant Threat
IP 45.198.224.5, operated by Vpsvault.host Ltd and routed through AS215925 in the United States, is a high-risk address with a threat level of 8/10 and a 95% confidence score, linked primarily to automated hacking probes, credential-scanning activity, and aggressive bot behavior detected across 1,940 separate incident reports from both honeypot sensors and community sources between May and August 2026.
The sustained volume of 1,940 reports over approximately four months reflects an ongoing, systematic campaign rather than opportunistic scanning, with an activity frequency rated 8/10 indicating persistent engagement with target infrastructure. Detection sources include 9 automated honeypot sensors and 11 community-based abuse reports, validating the findings across multiple independent monitoring systems. The reported threat categories consistently point toward authentication endpoint probing, web application vulnerability scanning, and suspicious automated HTTP client traffic using the Go-http-client user agent, alongside port-scan activity and specific probes for login and authentication paths.
The dominant hacking activity, representing the largest share of reports, signals an actor systematically mapping web-facing authentication interfaces and testing for vulnerable endpoints, while the concurrent bad-web-bot and SEO-bot signatures suggest the infrastructure may serve dual purposes including content scraping and search-engine manipulation schemes. The detection of an SSH session in progress on an expected port further indicates the host is actively maintaining interactive access capabilities, likely leveraging compromised credentials or brute-force techniques against exposed SSH services. This combination of automated probing, authentication-path scanning, and persistent presence creates a concrete risk of unauthorized access, credential compromise, or data exfiltration for any organization running exposed web login portals, SSH daemons, or content-management systems.
Site operators should immediately block or rate-limit this IP at the firewall or load-balancer level, enforce strong multi-factor authentication on all administrative and user-facing login interfaces, and implement bot-detection controls that specifically identify and throttle Go-http-client traffic and other non-browser automated clients. Deploying fail2ban or equivalent dynamic firewall rules on SSH services reduces the risk from credential-brute-force attempts, while web application firewalls configured to flag path-probing behavior on authentication endpoints provide an additional layer of defense against the scanning patterns observed from this source.