Extreme Threat
IP 93.152.208.42 is a critical-risk address originating from Bulgaria with a threat level of 10/10 and a 94% confidence score, linked to 1502 abuse reports detected across automated honeypot sensors over a four-month observation window between May and August 2026. The dominant malicious activity involves general hacking intrusion attempts and targeted port scanning reconnaissance, with the latter specifically probing Cisco ASA firewall infrastructure as part of pre-exploitation reconnaissance.
The volume and consistency of reports from 93.152.208.42 paint a clear picture of sustained hostile activity originating from AS211486, operated by Alferov Aleksey Aleksandrovich in Bulgaria. Detection data from 20 independent automated honeypot sensors recorded an activity frequency rating of 8/10, indicating near-continuous automated threat operations. Of the categorized incidents, hacking-related intrusion attempts accounted for 18 reports while port scanning activity contributed 2 additional reports, confirming that this address is engaged in both active exploitation attempts and the reconnaissance phase that precedes targeted attacks. The CiscoASA-specific port scan pattern observed in the detection data suggests the operator is systematically mapping network perimeters for known firewall vulnerabilities.
The hacking activity attributed to this IP represents a broad category of unauthorized access attempts and exploitation probing against exposed services. Port scanning, as demonstrated by the CiscoASA probe pattern, serves as a critical preliminary step in the attack lifecycle, allowing threat actors to identify accessible entry points before launching tailored exploitation attempts. The combination of persistent scanning and intrusion activity from a single source indicates a methodical approach to identifying and compromising vulnerable network infrastructure.
Administrators should immediately block 93.152.208.42 at the network perimeter firewall and configure intrusion detection systems to generate alerts for any future contact from this address. All internet-facing services should enforce strong, unique credentials and consider implementing multi-factor authentication to mitigate credential-based attack risks. Deploying tools such as fail2ban can help automate blocking of repeated connection attempts associated with scanning activity. Regular patching of Cisco ASA devices and other perimeter equipment is essential to eliminate the specific vulnerabilities that targeted scanning activity seeks to identify.