Significant Threat
IP 101.36.97.88 is a high-risk address associated with persistent hacking activity, having accumulated 311 abuse reports across automated honeypot sensors over approximately eleven months from August 2025 through June 2026.
The IP 101.36.97.88 is a high-risk address associated with persistent hacking activity, having accumulated 311 abuse reports across automated honeypot sensors over approximately eleven months from August 2025 through June 2026. The network operator, UCLOUD INFORMATION TECHNOLOGY HK LIMITED, manages AS135377, a Hong Kong-based cloud infrastructure provider whose routes terminate in the United Kingdom according to regional routing data. With a confidence score of 75% and an activity frequency rating of 6 out of 10, this address demonstrates consistent, repeated intrusion attempts rather than opportunistic scanning. All 311 reports are attributed to automated honeypot detection systems, indicating sustained automated engagement with vulnerable services exposed to the internet. The 20 most recent reports consistently classify the activity as general hacking, encompassing unauthorized access attempts and vulnerability exploitation patterns.
General hacking activity represents a broad category of intrusion behavior that includes brute-force authentication attacks, scanning for exposed vulnerabilities, and attempts to exploit misconfigured services. For network operators with internet-facing systems, each connection from an address like 101.36.97.88 poses a potential exploitation vector if services lack proper hardening. The sustained report volume over nearly a year indicates persistent automated scanning rather than one-time opportunistic probes, suggesting the address is part of an active infrastructure used for ongoing reconnaissance and exploitation attempts against exposed entry points.
Site operators should consider implementing automated blocking mechanisms such as fail2ban to dynamically ban IP addresses demonstrating brute-force patterns, enforce multi-factor authentication on all remote access services to prevent credential-based compromise, maintain rigorous patching schedules for internet-facing applications, and configure intrusion detection systems to generate alerts and optionally block traffic originating from this address to reduce attack surface exposure.