High Risk
IP 152.32.189.128 is a high-risk address operating from Hong Kong infrastructure that has generated 2,420 abuse reports over approximately one year, with its activity strongly consistent with automated hacking attempts targeting vulnerable network services. The sustained volume and frequency of connections from this IP warrant immediate defensive attention from any organization exposing services to the internet.
Automated honeypot sensors recorded the vast majority of these 2,420 reports, with every recent incident classified under the Hacking threat category. The IP originates from AS62610 (operated by ZEN-DPS) based in Hong Kong, and was first reported in September 2025 with continued activity through August 2026. The threat level of 8/10 combined with an activity frequency rating of 8/10 and an 86% confidence score indicates a persistent, well-documented threat actor that has maintained consistent scanning and intrusion behavior over an extended period. The network operator has not demonstrated effective abuse response despite the substantial volume of reports, suggesting either deliberate tolerance of malicious activity or inadequate infrastructure governance.
The dominant Hacking classification encompasses a broad spectrum of unauthorized access attempts, vulnerability exploitation, and intrusion activity that typically includes port scanning, credential guessing, exploitation of known software flaws, and probing for misconfigured services. The abstract "attack connection" pattern suggests automated exploitation attempts against exposed endpoints, likely including services such as SSH, Telnet, HTTP interfaces, or database ports that are commonly targeted for initial compromise. For an organization running any exposed service, even a small number of successful probes from an IP with this reputation could indicate imminent compromise or sustained reconnaissance activity preceding more sophisticated attacks.
Network operators should block 152.32.189.128 at the firewall or edge router level, implement strict inbound connection allowlisting where feasible, and enforce strong multi-factor authentication on all externally accessible services to limit the impact of any successful intrusion attempt. Deploying fail2ban or similar dynamic blocking tools can automatically respond to the repetitive connection patterns this IP demonstrates. Security teams should audit exposed services for unnecessary open ports, apply vendor-released patches promptly, and monitor logs for any authentication failures or anomalous requests originating from this address. Ongoing threat intelligence feeds should be consulted to track whether this IP's activity profile changes or if related infrastructure emerges.