Elevated Risk
IP 152.32.172.108 is a high-risk address operating from Hong Kong that has been linked to 2,380 reported hacking incidents, representing a persistent and significant threat to exposed network services worldwide. With a threat level of 8 out of 10 and an activity frequency score of 8 out of 10, this IP demonstrates sustained aggressive behavior that warrants immediate defensive attention from network administrators and security teams managing publicly accessible infrastructure.
According to abuse reports spanning nearly a year, automated honeypot sensors detected and documented 2,380 separate incidents attributed to this single address between September 2025 and August 2026. All reported threat categories consist of general hacking activity, including intrusion attempts, exploitation attempts targeting known vulnerabilities, and unauthorized access attempts against exposed services. The IP is registered to ZEN-DPS under autonomous system AS62610, and the consistency of reporting across twenty separate honeypot sources establishes an 86% confidence score that this address is deliberately involved in malicious reconnaissance and attack operations.
The dominant hacking classification indicates that this IP is actively engaged in probing networks for weaknesses, attempting to exploit vulnerable services, and seeking unauthorized entry into systems. This pattern of sustained attack behavior poses a concrete risk to any exposed SSH, Telnet, HTTP, or other network services that rely on password-based authentication or unpatched software. Attackers leveraging such infrastructure typically employ automated tools to scan large IP ranges, meaning exposure to this address could result in repeated credential-guessing attacks, vulnerability scanning, or exploitation attempts against misconfigured or outdated services.
Site operators should implement immediate defensive controls upon encountering this IP reputation in their logs. Enforce strong, unique authentication credentials and disable default administrative accounts where feasible. Deploy rate-limiting rules and automated IP blocking using defensive tools such as fail2ban to mitigate brute-force attempts. Maintain continuous traffic monitoring, regularly audit authentication logs for signs of intrusion, and ensure all systems are current with security patches to minimize vulnerability exposure that this address may attempt to exploit.