Critical Alert
36.25.240.114 is a critical-risk IP address operating from China Telecom's Hangzhou IDC infrastructure (ASN AS58461) that has been linked to 210 total abuse reports and 20 confirmed hacking attempts detected between March and April 2026. With a threat level of 10/10 and a 94% confidence score, this address represents a significant and persistent danger to any exposed network services.
The detection data originates exclusively from automated honeypot sensors, which recorded a consistent pattern of TCP stream anomalies over the two-month reporting window. The 210 total reports indicate sustained hostile activity rather than opportunistic scanning, while the activity frequency rating of 4/10 suggests periodic, deliberate engagement with target systems rather than random noise. The network operator, CT-HangZhou-IDC, hosts infrastructure commonly associated with both legitimate enterprise services and threat actors leveraging China's extensive broadband footprint for international operations.
The dominant threat category, hacking activity, manifests in Suricata alerts indicating receipt of TCP FIN and RST packets for sessions that do not exist. This pattern is characteristic of TCP sequence number probing, firewall or IDS state-enumeration attempts, and reconnaissance techniques designed to map the response characteristics of target systems. Attackers use these methods to identify filtered versus open ports, detect the presence of intrusion detection systems, and prepare for subsequent targeted exploitation by understanding how the victim's stack responds to malformed connection-teardown requests.
Network defenders should immediately block this IP at the firewall level given its maximum threat classification and confirmed hostile intent. Implementing authentication hardening such as key-based SSH access, non-standard port configuration, and fail2ban or similar dynamic blocking tools will substantially reduce vulnerability to the reconnaissance patterns observed. Regular monitoring of honeypot telemetry and Suricata state alerts will help identify follow-up activity from adjacent address space within AS58461, and organizations should ensure IDS signatures covering TCP stream anomalies remain current to detect any refined iterations of these techniques.