Elevated Risk
IP 152.32.156.158 is a high-risk address operated by UCLOUD INFORMATION TECHNOLOGY HK LIMITED and routed through Indian infrastructure, with a threat level of 8/10 reflecting sustained malicious activity primarily characterized by hacking intrusion attempts. The IP has accumulated 334 total abuse reports from automated honeypot sensors over approximately seven months, with 20 of the most recent reports categorizing its behavior as hacking activity alongside one web application attack report. This report volume and threat classification make this address a clear candidate for blocking in security stacks and raise significant concerns about its IP reputation among threat intelligence consumers.
Community-sourced reporting and automated honeypot detections indicate that 152.32.156.158 first appeared in security feeds in December 2025 and continued generating reports through June 2026, suggesting persistent rather than opportunistic malicious behavior. The network AS135377 operated by UCLOUD INFORMATION TECHNOLOGY HK LIMITED has been associated with this address throughout the observation window, placing the infrastructure in India despite the Hong Kong-based operator. Suricata intrusion detection systems logged multiple signature matches against this IP including TLS protocol anomalies, application-layer protocol mismatches, and web application probing patterns, all indicating active reconnaissance and exploitation attempts against exposed services.
The dominant threat category of hacking encompasses unauthorized access attempts, vulnerability exploitation, and intrusion activity that can compromise systems ranging from exposed SSH services to administrative interfaces. The detected attack patterns involving TLS record anomalies and protocol detection failures suggest this actor is actively probing encrypted service configurations for weaknesses or misconfigurations to exploit. Web application attacks, while less frequently reported, target application-layer vulnerabilities that could enable data exfiltration, session hijacking, or server compromise depending on the exposed application stack.
Site operators should implement immediate blocking of IP 152.32.156.158 at the network perimeter firewall or through reputation-based blocklists, and should audit publicly accessible services for exposure to the TLS and protocol anomalies this IP has demonstrated capability to probe. Deploying fail2ban or similar dynamic firewall rules can automatically block repeated connection attempts from addresses exhibiting scanning behavior. Web application firewalls should be configured to detect and mitigate the protocol mismatch patterns associated with this address, and all exposed services should follow current patch management schedules to reduce vulnerability surfaces that such scanning activity targets.