Severe Risk
IP address 117.50.226.213 is a critical-risk address linked to sustained SSH brute-force attacks and broader hacking activity originating from China Unicom's Beijing province network in AS4808, with 170 abuse reports filed over the first half of 2026 at a 94% confidence rating and an activity frequency score of 8 out of 10.
The IP was first reported in January 2026 and continued generating reports through June 2026, with 20 automated honeypot sensors confirming the malicious activity. Of the reported threat categories, Hacking accounts for 20 reports and SSH-related activity comprises 16 reports, while 2 reports classify the address as an Exploited Host. Suricata detection signatures specifically captured ongoing SSH sessions on expected ports alongside active brute-force attempts, confirming that automated honeypot infrastructure directly observed the attacking behavior targeting secure shell services.
The dominant SSH threat category indicates systematic attempts to compromise publicly accessible servers through credential guessing and protocol exploitation. The presence of Exploited Host classifications alongside the brute-force activity suggests the address may be functioning as part of an automated attack infrastructure, either operating under adversarial control or serving as a compromised asset in broader credential-stuffing campaigns. The sustained six-month activity window demonstrates persistent rather than opportunistic targeting, meaning any exposed SSH service within scanner range faces repeated automated intrusion attempts.
Site operators maintaining publicly accessible SSH services should immediately block this address at the network perimeter and consider implementing fail2ban or equivalent intrusion prevention tools to automatically ban IPs exhibiting brute-force patterns. Authentication hardening measures including key-based authentication, non-default ports, and disabled root login significantly reduce attack surface. Continuous monitoring of authentication logs for the source IP pattern helps detect compromise if the blocking is circumvented. Organizations should also ensure all SSH implementations remain current with security patches to defend against known protocol vulnerabilities.