Extreme Threat
IP 152.32.197.159 is assessed as a critical-risk address with a maximum threat level of 10/10, associated with sustained hacking activity, web application probing, and IoT targeting originating from Brazilian infrastructure despite registration under a Hong Kong-based cloud provider.
Security monitoring systems recorded 283 abuse reports attributed to this IP across a nine-month window from October 2025 through June 2026, with detection originating from 20 distinct automated honeypot sensors distributed across community monitoring networks. The dominant threat classification centres on general hacking activity, supplemented by isolated reports of web application attacks, IoT-targeted probing, and exploited host indicators. Detected attack patterns include ElasticPot web application probes, Suricata intrusion-detection alerts signalling protocol mismatches in both directions, and TLS anomalies indicative of exploit or malware delivery attempts. Despite the high report volume and maximum threat score, the reported activity frequency of 3/10 suggests periodic rather than continuous engagement, consistent with a scanning campaign that cycles through target sets. The AS135377 network registered to UCLOUD INFORMATION TECHNOLOGY HK LIMITED presents an interesting discrepancy between its Hong Kong registration and the Brazilian geolocation, a pattern sometimes associated with routed or proxied infrastructure.
The hacking activity linked to this IP represents unauthorized access attempts, vulnerability exploitation, and intrusion scanning behaviours that pose a concrete risk to any exposed service accepting connections from Brazilian address space. Web application probing specifically targets weaknesses in application-layer software, including injection points and configuration errors that could yield remote code execution or data exfiltration if successfully exploited. The IoT-targeting component signals interest in internet-connected devices with historically weak security postures, potentially attempting credential stuffing against default credentials or exploiting known firmware vulnerabilities. The presence of TLS anomaly alerts further suggests this actor may be attempting to deliver malicious payloads over encrypted channels to evade detection.
Organizations with internet-facing assets should treat this IP as a confirmed threat source warranting immediate blocking at the network perimeter. Implementing automated blocking mechanisms using tools such as fail2ban or equivalent intrusion-prevention systems can proactively deny connection attempts without manual intervention. Network segmentation isolating web-facing applications and IoT devices from core infrastructure limits the blast radius of any successful compromise. Maintaining comprehensive logging of connection attempts from this address range supports forensic analysis if an intrusion attempt succeeds despite defensive measures.