Critical Threat
IP 142.93.224.108, hosted on DigitalOcean infrastructure in the Netherlands under ASN 14061, is a high-risk threat actor associated with SSH brute-force attacks and general hacking activity, backed by 516 abuse reports and a 94% confidence score.
Automated honeypot sensors detected this address conducting sustained malicious activity throughout February 2026, logging 17 separate reports across both SSH and hacking categories. The activity frequency rating of 8/10 and the substantial total report volume confirm persistent automated attack behavior originating from DigitalOcean's network rather than isolated reconnaissance. The high report count relative to the recent detection window indicates intensive, repeated scanning and brute-forcing campaigns against SSH services across numerous targets.
SSH brute-force attacks rank among the most prevalent initial access vectors used by threat actors to compromise servers. Attackers systematically attempt weak or default credential combinations to gain unauthorized shell access, potentially deploying backdoors, exfiltrating data, or leveraging the compromised host as a pivot point for deeper network intrusion. The volume of reports associated with this IP suggests an aggressive, automated campaign likely conducted via dictionary-based credential stuffing tools.
Site operators should immediately block or rate-limit inbound connections from 142.93.224.108 at the firewall or network edge and audit authentication logs for any matching connection attempts. Switching to key-based SSH authentication, disabling direct root login, and moving SSH to a non-standard port dramatically reduces brute-force exposure. Deploying automated tools such as fail2ban can detect and ban repeated authentication failures in real time. Maintaining current patches, implementing intrusion detection monitoring, and enforcing strong password policies provide layered defense against this and similar threat sources.