Notable Threat
IP 152.32.156.50 is a critical-risk address with a threat level of 10 out of 10, assessed at 73 percent confidence, that has generated 263 abuse reports across 20 automated honeypot sensors since August 2025. The IP originates from India and is routed through network operator UCLOUD INFORMATION TECHNOLOGY HK LIMITED, with activity most recently documented in May 2026.
Detection data reveals 263 total reports spanning approximately nine months, with the vast majority of recent reports categorizing the activity as general hacking attempts and a smaller subset specifically targeting Internet of Things infrastructure. The attack-pattern signatures include TLS protocol anomalies, with Suricata sensors flagging invalid record types that indicate malformed or manipulative traffic designed to probe or bypass encryption implementations. While the overall activity frequency scores only 3 out of 10, the volume of reports and consistent threat categorization demonstrate persistent, automated scanning behaviour directed at exposed services worldwide.
The dominant hacking classification encompasses a broad range of intrusion attempts, vulnerability exploitation and unauthorized access probing. Combined with IoT targeting activity, this IP poses a concrete risk to exposed network endpoints, particularly unpatched servers, legacy systems with known vulnerabilities, and poorly secured connected devices. Malformed TLS record attempts may signal reconnaissance efforts to identify implementation weaknesses or preparation for more sophisticated man-in-the-middle exploitation. Organizations with exposed services or IoT deployments represent the primary attack surface for this threat actor.
Site operators should immediately block or heavily rate-limit connections from this IP at the network perimeter firewall level and implement fail2ban or equivalent dynamic blocking tools. All exposed services should be audited for compliance with current security patches, with priority given to TLS implementations and IoT device firmware. Network segmentation isolating IoT devices from critical infrastructure is strongly recommended. Continuous traffic monitoring for the observed attack signatures will enable rapid identification of follow-up activity from this or related threat sources.