Extreme Threat
IP 113.193.234.210, originating from Tikona Infinet Ltd. infrastructure in India, is assessed as a critical-risk address with a maximum threat score of 10/10 based on 359 independent abuse reports accumulated over approximately eight months. The dominant threat activity consists of persistent SSH brute-force attacks, accounting for the overwhelming majority of recent reports. With an 80% confidence rating and consistent activity spanning from October 2025 through May 2026, this IP presents a severe and ongoing risk to any publicly accessible SSH services.
The IP has been flagged by 20 automated honeypot sensors across the security community, generating 359 total reports with an activity frequency rated at 4/10. Detection patterns reveal concentrated SSH brute-force attempts, with automated defensive systems such as fail2ban recording approximately 83 violations across multiple monitored instances. Suricata intrusion-detection alerts specifically identified active SSH sessions on expected non-standard ports combined with credential-guessing behavior. The geographic origin in India and the AS45528 network allocation to Tikona Infinet Ltd. situate this actor within a commercial broadband ISP environment, consistent with either a compromised residential endpoint or a deliberately provisioned attack platform.
SSH brute-force attacks represent one of the most common and effective initial-access vectors employed by threat actors to compromise servers. By systematically attempting credential combinations against exposed SSH daemons, attackers seek to bypass authentication and gain unauthorized shell access to target systems. Successful compromise typically enables data exfiltration, malware deployment, lateral movement within networks, or integration into botnets. The pattern of multiple concurrent brute-force campaigns detected against honeypot infrastructure suggests this address is actively participating in automated attack operations, potentially as part of a distributed credential-stuffing campaign or a compromised host being weaponized without the owner's knowledge.
Network defenders should immediately block 113.193.234.210 at the firewall or network perimeter to eliminate this threat vector entirely. Organizations running publicly accessible SSH services should enforce key-based authentication exclusively, disable root login, and change the default port to a non-standard value. Implementing fail2ban or similar dynamic blocking tools provides automated response to brute-force patterns. Regular monitoring of authentication logs for the originating IP and similar source addresses will help identify ongoing campaigns. Providers receiving abuse notifications regarding this address should consider investigating whether the customer endpoint has been compromised and requires remediation.