Critical Alert
IP address 103.14.32.75 is a high-risk address assessed at 8/10 threat level with a 94% confidence score, persistently linked to SSH brute-force attacks and broader hacking activity as documented by 173 total abuse reports from automated honeypot sensors, making it a clear candidate for blocking on any exposed SSH service.
The IP originates from Singapore and operates through AS135377 under UCLOUD INFORMATION TECHNOLOGY HK LIMITED, with activity tracked from December 2025 through February 2026 at a frequency rating of 8/10, indicating sustained and deliberate hostile probing rather than isolated incidents. Detection sources span 20 automated honeypot sensors reporting evenly across two threat categories: SSH attempts (14 reports) and Hacking activity (14 reports), with honeypot event logs capturing both brute-force sequences and suspicious command input patterns, confirming active exploitation attempts against exposed services.
SSH brute-force attacks represent a direct pathway to server compromise through systematic password guessing or exploitation of known SSH vulnerabilities, and when combined with general hacking activity encompassing intrusion attempts and vulnerability exploitation, this IP poses a concrete risk of unauthorized server access to any organisation running an exposed SSH daemon. The volume and consistency of reports against honeypot infrastructure indicates automated tooling is being employed, and a successful authentication would grant an attacker persistent shell access with the privileges of the compromised user account.
Site operators should immediately block 103.14.32.75 at the firewall level, implement key-based authentication as the sole login method, consider relocating SSH to a non-standard port, and deploy fail2ban or equivalent tooling to automatically ban IPs after a configurable number of failed authentication attempts. Additionally, disabling direct root login and enforcing strong passphrase policies across all accounts significantly reduces the attack surface exposed to credential-guessing campaigns of this nature.