Extreme Threat
IP 103.210.21.178 is a critical-risk address actively conducting SSH brute-force attacks against servers worldwide, with a threat level of 10/10 and 445 abuse reports filed against this single Singaporean IP over approximately seven months of sustained activity. The address, registered to UCLOUD INFORMATION TECHNOLOGY HK LIMITED under ASN AS135377, presents an 8/10 activity frequency, indicating near-continuous malicious engagement with target systems since its first logged detection in November 2025.
Analysis of the available detection data reveals consistent patterns consistent with automated credential stuffing operations targeting the SSH service. Automated honeypot sensors recorded 20 distinct attack events from this IP, each generating multiple violation alerts ranging from 25 to 36 per instance. The repeated detection across multiple honeypot sensors over a seven-month window from November 2025 through May 2026 demonstrates persistent, deliberate targeting rather than opportunistic scanning, with 445 total community reports confirming sustained abusive behavior originating from this UCLOUD-operated address.
SSH brute-force attacks systematically attempt username and password combinations to compromise servers running the SSH daemon, exploiting weak credentials, default usernames, or unpatched authentication mechanisms. Successful unauthorized access grants attackers command-level control over the target system, enabling data exfiltration, lateral movement within networks, deployment of persistent backdoors, or integration into botnets for distributed denial-of-service operations. The sustained, high-volume nature of the activity detected from 103.210.21.178 suggests an automated infrastructure designed for continuous credential testing against exposed SSH endpoints.
Network operators should immediately block 103.210.21.178 at the firewall level and implement fail2ban or equivalent intrusion prevention tools to dynamically ban repeated offenders. Administrators exposing SSH services should enforce key-based authentication exclusively, disable root login, change the default SSH port to a non-standard value, and implement rate-limiting on authentication attempts. Continuous monitoring of authentication logs for this IP address and similar scanning activity from adjacent UCLOUD address space will further reduce exposure to these persistent automated attacks.