Severe Risk
IP 103.157.127.7, registered to MICRONET GIGAFIBER PRIVATE LIMITED in India, is a critical-risk address associated with general hacking activity, scoring the maximum threat level of 10 out of 10 based on 158 total reports submitted through automated honeypot sensors during September 2025.
The IP address was first and most recently reported in September 2025, with 20 of those reports specifically categorizing the observed activity as hacking attempts. All detections originated from automated honeypot sensors, indicating systematic, scripted intrusion behavior rather than opportunistic manual probing. Despite the high volume of abuse reports, the activity frequency score of 0/10 suggests these reports represent discrete incidents rather than sustained continuous bombardment. The 63% confidence score reflects that while the threat indicators are serious, the attribution to this specific actor carries some uncertainty typical of transient cloud-hosted infrastructure. The AS146904 network belonging to a regional internet service provider in India is a common profile for threat actors leveraging affordable, disposable broadband connections for malicious operations.
Hacking activity in this context encompasses unauthorized access attempts, vulnerability exploitation, and intrusion-level probes against exposed services. This category of threat poses significant risk because successful exploitation can result in complete system compromise, data exfiltration, or pivoting to internal network resources. The honeypot detections confirm the IP is actively scanning and probing external attack surfaces, likely as part of automated scanning campaigns that systematically test for known vulnerabilities or misconfigurations across vast numbers of target addresses.
Site operators should immediately block or rate-limit traffic from this IP address at the firewall or network edge. Enforcing strong authentication mechanisms—including key-based authentication for SSH and multi-factor authentication for administrative interfaces—substantially reduces the risk of successful intrusion. Deploying fail2ban or similar dynamic blocking tools can automatically respond to repeated authentication failures and suspicious request patterns. Keeping all systems patched and running an intrusion detection system helps catch exploitation attempts before they succeed. Regular monitoring of authentication logs for source IPs matching this address or adjacent ranges provides early warning if the actor attempts to re-establish contact through different infrastructure.