Elevated Risk
IP 128.1.32.99 is a critical-risk address operating from Taiwan through UCLOUD INFORMATION TECHNOLOGY HK LIMITED (AS135377), with 181 total abuse reports logged across 20 automated honeypot sensors between August 2025 and May 2026, indicating sustained hostile activity dominated by web application reconnaissance and probing. The threat level of 10/10 reflects the volume and consistency of detected attacks, primarily targeting web-facing services alongside noted interest in IoT and ICS infrastructure.
The detection profile for 128.1.32.99 spans approximately nine months of continuous reporting, with honeypot sensors across multiple locations identifying the address repeatedly attempting web application exploitation, general intrusion activity, and targeted scanning for Internet of Things and industrial control systems. Web application attacks account for the majority of recent reports, followed by broader hacking activity and a smaller but notable IoT-directed component. The cross-category detection pattern across twenty independent sensor sources raises the confidence assessment to 66%, suggesting automated tooling engaged in persistent reconnaissance rather than isolated opportunistic probes.
Web application attacks exploit vulnerabilities in exposed HTTP services, including injection flaws, authentication bypasses, and configuration weaknesses that can lead to data compromise or server control. The combined interest in IoT and ICS environments alongside web-layer attacks indicates a dual-purpose scanning operation that catalogues both traditional web services and connected device surfaces for potential future exploitation. The sustained nature of this activity over months, despite a relatively low individual attack frequency of 2/10, suggests methodical rather than burst-driven hostile infrastructure.
Network operators should block or severely rate-limit traffic from this address at the perimeter firewall, implement web application firewall rules to deflect the observed attack patterns, and segment IoT and ICS devices onto isolated network zones with strict egress controls. Keeping web servers, applications, and firmware current with security patches, enforcing strong authentication on all exposed services, and monitoring logs for the patterns associated with this IP will reduce exposure to the reconnaissance and exploitation activity documented here.