Maximum Danger
IP 103.172.146.170 is a high-risk address linked to automated SSH brute-force attacks, originating from Indian network infrastructure operated by Web Werks India Pvt. Ltd. With a threat level rated at the maximum and over ten thousand abuse reports logged across a compressed two-month window from November to December 2025, this IP represents one of the most actively reported sources of credential-guessing activity currently observed in public threat feeds.
The data confirms 103.172.146.170 generated 10,440 reports from 20 distinct automated honeypot sensors, with the dominant threat category being general hacking activity and SSH intrusion attempts specifically. Despite the extraordinarily high report volume, the activity frequency metric of zero out of ten suggests this IP may operate intermittently rather than continuously, concentrating bursts of malicious traffic in specific periods before becoming dormant. The AS133296 allocation places this address within a commercial hosting environment in India, a network operator profile consistent with both compromised infrastructure and deliberately provisioned attack platforms. The confidence score of 59 percent indicates moderate certainty in attribution, acknowledging that some reported activity could originate from NAT gateways or shared IPs masking multiple sources.
SSH brute-force activity poses a direct and severe threat to any exposed server management interfaces. Attackers deploy automated tooling to cycle through common username-password combinations against port 22, exploiting weak or default credentials to gain unauthorized shell access. Successful authentication grants adversaries a foothold within internal networks, enabling data exfiltration, lateral movement, cryptojacking deployment, or use of the compromised host as a pivot point for further attacks. The scale of reports against 103.172.146.170 indicates persistent automated scanning, meaning any exposed SSH service in range of this address faces continuous credential-guessing pressure.
Organizations should immediately block 103.172.146.170 at the network perimeter firewall and implement deny-by-default rules at the host level. Configuring fail2ban or equivalent intrusion-prevention tools to automatically ban IPs after repeated authentication failures provides adaptive defense against brute-force campaigns. SSH hardening should include disabling password-based authentication entirely in favor of asymmetric key pairs, changing the default listening port, and disabling root login. Continuous monitoring of authentication logs and deploying network-level rate limiting on SSH connections will further reduce exposure to credential-guessing threats from this and similar hostile addresses.