High Risk
IP 103.29.185.162, originating from PT Pascal Indonesia's AS56260 network in Indonesia, presents a high-risk threat profile with a threat level of 8/10, supported by 449 total abuse reports and a 69% confidence score. The address has been flagged by automated honeypot sensors and community reports across 20 distinct sources since August 2025, with the most recent detections recorded in May 2026, indicating persistent malicious activity over an extended period despite a relatively low activity frequency rating of 2/10.
The evidence base for this IP is substantial and multi-sourced. Of the recorded threat events, 14 were classified as general hacking activity involving intrusion attempts and exploitation attempts against exposed services, while 6 were specifically identified as brute-force authentication attacks. Eighteen of the 20 report sources are automated honeypot sensors, supplemented by 2 community submissions, collectively painting a consistent picture of an address actively engaged in credential-guessing and vulnerability probing against internet-facing systems.
The dominant attack pattern associated with this IP reflects systematic attempts to gain unauthorized access to remote administration interfaces. Brute-force attacks of this nature target authentication portals by cycling through password combinations, and when combined with broader hacking activity that includes exploitation of known vulnerabilities, the risk to an exposed service is considerable. Even a low activity frequency does not diminish the danger to an individual target system that lacks adequate rate limiting or account lockout protections.
Site operators with internet-facing services should treat connections from this address as hostile. Implementing fail2ban or equivalent loginAttempt mitigation tools to dynamically block repeated authentication failures, enforcing multi-factor authentication on all remote access portals, and applying strict rate-limiting rules at the network perimeter will substantially reduce exposure. Keeping systems patched against known vulnerabilities and monitoring logs for the detection signatures associated with brute-force and intrusion patterns observed from this source are critical defensive steps.