Critical Alert
IP 117.156.229.133, registered to China Mobile Communications Group Co., Ltd. under autonomous system AS9808 in China, presents a maximum threat level of 10/10 based on 249 reported abuse incidents, with its activity exclusively catalogued as SSH brute-force attempts against exposed honeypot sensors between January and April 2026. The IP operates from a major Chinese telecommunications carrier network, giving it access to substantial broadband infrastructure for sustained scanning and authentication-guessing campaigns.
Detection data sourced entirely from automated honeypot sensors recorded 20 distinct SSH connection attempts attributed to this address, each triggering fail2ban defensive responses after repeated authentication failures. The attack pattern logs show consistent sshd brute-force behaviour with 25 recorded violations per detection cycle, indicating systematic password-guessing methodology rather than opportunistic probe-and-leave activity. Despite the high volume of aggregate reports, the recorded activity frequency metric of 0/10 suggests that the most recent engagement with defensive infrastructure has ceased, possibly indicating the campaign concluded or shifted to alternative infrastructure. The 78% confidence score reflects probable but not definitively confirmed attribution given the honeypot-only reporting source.
SSH brute-force attacks represent a persistent threat to any internet-exposed server running the Secure Shell protocol, particularly those retaining default port 22, permitting password-based authentication, or allowing root administrative access. The real-world risk from an address conducting such attacks includes unauthorized server entry, lateral movement within networks, data exfiltration, cryptocurrency mining deployment, and botnet recruitment. The repeated nature of the detected attempts against honeypot infrastructure confirms this address actively cycles through credential combinations in hopes of compromising misconfigured or weakly-protected Linux and network devices.
Site operators should immediately block IP 117.156.229.133 at the firewall level given its confirmed malicious history, while ensuring fail2ban or equivalent intrusion-prevention tools are configured to auto-ban repeat offenders targeting sshd services. Network defenders should enforce key-based authentication exclusively, change the default SSH listening port, disable direct root login, and implement strong password policies or certificate-only access. Continuous monitoring of authentication logs and rate-limiting incoming SSH connections from untrusted networks will substantially reduce exposure to similar scanning activity originating from this address space.