High Risk
IP address 85.217.149.12 is a high-risk Canadian address associated with 534 abuse reports and active SSH intrusion activity, representing a significant threat to any exposed service. The address, operating through AS209334 under Modat B.V., demonstrates consistent malicious behavior with a threat level of 8 out of 10 and activity frequency rated at 8 out of 10, making it a persistent risk in the threat landscape. The confidence score of 79% based on automated honeypot sensor data and community reports provides reasonable attribution for this observed activity. Detection systems flagged the address multiple times for attempting unauthorized access, with the predominant attack vector being connection attempts and anomalous SSH session patterns on non-standard ports.
The report volume of 534 incidents spans a six-month active period from January 2026 through June 2026, indicating sustained and deliberate targeting rather than opportunistic scanning. All 534 reports were generated through automated honeypot sensors, confirming this is a systematic automated threat rather than manual probing. The attack pattern analysis reveals specific detection signatures related to SSH sessions on unusual ports, suggesting the actor is employing techniques designed to evade standard detection mechanisms by avoiding default service ports. The geographic attribution to Canada through AS209334 provides network-level context, though threat actors frequently utilize infrastructure in diverse jurisdictions to obscure origin.
Hacking activity of this nature poses concrete risks to any organization running accessible SSH services, particularly those on non-standard ports where administrators may assume reduced exposure. The detected patterns indicate automated brute-force or credential-stuffing operations attempting to gain unauthorized shell access to systems. Successful compromise of SSH access provides threat actors with persistent remote access, lateral movement capabilities, and potential control over sensitive data or critical infrastructure. The sustained activity over six months demonstrates persistence, suggesting this IP is part of coordinated infrastructure rather than a transient opportunistic scanner.
Site operators should immediately block 85.217.149.12 at the network perimeter firewall and implement deny-by-default access controls for unused services. Enabling fail2ban or similar dynamic blocking tools on SSH services, even those running on non-standard ports, provides automated response to repeated authentication failures. Enforcing key-based authentication exclusively, disabling password authentication, and implementing two-factor authentication for administrative access significantly reduces credential-based attack success rates. Regular monitoring of authentication logs for this address and similar patterns on unusual SSH ports will help identify ongoing targeting attempts and potential configuration weaknesses being exploited.