Critical Threat
IP 152.32.202.163 is a critical-risk address originating from Japan with a threat level of 10 out of 10, associated with 405 total abuse reports and active SSH brute-force intrusion attempts targeting exposed servers.
The IP is registered to UCLOUD INFORMATION TECHNOLOGY HK LIMITED on autonomous system AS135377 and has been flagged by 20 separate automated honeypot sensors since September 2025. The reported threat categories include general hacking activity (15 reports) and specifically SSH-related attacks (5 reports), with the dominant attack pattern identified as SSH brute-force attempts and honeypot interaction events. Despite a notably low current activity frequency score of 0 out of 10, the sheer volume of historical reports underscores this address's persistent threat reputation and its repeated targeting of network services worldwide.
SSH brute-force attacks represent a prevalent initial access vector where threat actors systematically attempt authentication against exposed Secure Shell services using common or leaked credential combinations. Even with a 60% confidence score, the high volume of independent detections from multiple honeypot sensors indicates deliberate, automated scanning behavior consistent with botnet-driven credential stuffing campaigns. An exposed SSH service receiving repeated authentication attempts faces elevated risk of unauthorized access, lateral movement, data exfiltration, or incorporation into a distributed attack infrastructure.
Network operators should block IP 152.32.202.163 at the perimeter firewall and implement fail2ban or equivalent dynamic blocking mechanisms to automatically ban repeated failed authentication sources. Organizations running SSH services should enforce key-based authentication exclusively, disable root login, change the default port, and apply strict rate-limiting on authentication endpoints. Continuous monitoring of authentication logs for this address and similar scanning patterns will help detect ongoing targeting campaigns before a successful compromise occurs.