Critical Threat
IP 103.158.206.141 is a critical-risk address operated by MS Bhola Dot Net in Bangladesh (AS141417) that has been extensively linked to SSH brute-force attacks and broader hacking activity, with 167 abuse reports logged between January and May 2026 at an activity frequency rated 8 out of 10. The volume, consistency and sophistication of the targeting make this one of the most clearly hostile IPs observed in recent open-source intelligence feeds.
Automated honeypot sensors recorded 20 distinct detection events tied to this address, with the majority categorised as SSH intrusion attempts. Of the 40 classified threat reports submitted, 20 referenced general hacking activity including exploitation attempts, 19 were specifically attributed to SSH brute-force scanning, and one report classified the host itself as compromised and exploited. The January-to-May reporting window spans five months of sustained hostile activity, indicating a persistent automated campaign rather than a transient or opportunistic probe.
SSH brute-force attacks systematically attempt to gain unauthorised server access by cycling through credential combinations against the Secure Shell service. The associated Suricata alerts confirm active sessions in progress on expected SSH ports, which suggests the operator has successfully authenticated or is actively enumerating credentials on exposed targets. When combined with the hacking category classifications, this pattern indicates the IP may be running a multi-vector intrusion toolkit capable of both credential stuffing and vulnerability exploitation, posing a direct risk to any publicly accessible SSH daemon.
Administrators should block 103.158.206.141 at the firewall or network edge immediately. Deploy key-based authentication exclusively for SSH access, change the default port away from 22, and enforce strong passphrase policies to render credential-guessing campaigns ineffective. Implementing fail2ban or equivalent log-analysis tools to automatically ban repeated connection attempts after a threshold is reached will substantially reduce exposure. Regular audit of authentication logs for source IP 103.158.206.141 and any associated scanning behaviour will help determine whether any prior compromise attempts succeeded.