Severe Risk
IP 106.75.137.178 is a critical-risk address that has generated 1234 abuse reports over approximately ten months, with automated honeypot sensors flagging sustained hacking activity including spurious TCP retransmission patterns consistent with active intrusion tooling. The IP originates from CHINANET Guangdong province network (ASN AS58466) in China and carries a threat-level score of 10 out of 10, indicating severe and ongoing malicious behaviour against exposed services.
The detection volume of 1234 reports represents exceptionally high hostile attention, with an activity frequency rated 8 out of 10, placing this address among the most persistent threats documented in community telemetry. All 20 most recent reports classify the activity as general hacking, encompassing intrusion attempts and exploitation of vulnerabilities. The Suricata alert signature "SURICATA STREAM spurious retransmission" indicates that the attacking host is generating anomalous TCP stream behaviour, a technique sometimes employed by automated exploitation frameworks to probe or circumvent stateful inspection. First reported in September 2025 and most recently active in July 2026, this IP has sustained a multi-month campaign without apparent cessation, suggesting either a dedicated threat actor or a compromised host leveraged as a persistent attack platform within the CHINANET infrastructure.
The dominant hacking classification for IP 106.75.137.178 signals that this address is engaged in active reconnaissance and intrusion attempts rather than opportunistic scanning alone. Spurious TCP retransmissions can indicate session hijacking attempts, man-in-the-middle positioning, or simply aggressive brute-force tooling that ignores proper TCP state management. For any service exposed to this IP, the risk of unauthorized access attempts, credential stuffing, or exploitation of known vulnerabilities is substantial given the sustained frequency and volume of reported contacts. The 86% confidence score reflects strong corroboration across multiple automated honeypot sensors, making this attribution reliable enough to justify immediate defensive action.
Site operators should block 106.75.137.178 at the firewall level given its maximum threat rating and sustained activity profile. Implementing fail2ban or equivalent rate-limiting daemons can automatically ban repeated login failures from this source. Authentication portals and remote access services facing the internet should enforce strong credential policies, multi-factor authentication, and account lockout thresholds to neutralise brute-force vectors. Continuous monitoring of inbound connection logs from CHINANET address space is advisable, and any matching Suricata stream alerts should trigger automated blocking rules to prevent session-level exploitation attempts.