Extreme Threat
IP 152.32.206.87 presents a maximum threat level of 10/10 based on 336 documented abuse reports from automated honeypot sensors spanning September 2025 through June 2026, making it a confirmed high-risk address associated with sustained hacking activity, unauthorized access attempts, and vulnerability exploitation. The IP is routed through AS135377 (UCLOUD INFORMATION TECHNOLOGY HK LIMITED) and geolocated to the United States, a configuration frequently observed in bulletproof hosting environments where infrastructure operators knowingly accommodate malicious traffic despite geographic mismatches with their registered jurisdiction.
The volume of reports filed against 152.32.206.87 reflects coordinated hostile activity detected across multiple sensor platforms, with all 336 reports attributed to automated honeypot infrastructure that monitors exposed services. The 73% confidence score indicates strong certainty regarding the IP's malicious classification while acknowledging minor uncertainty in attribution specifics. Notably, the activity frequency registers at only 3/10, suggesting the address conducts targeted probing rather than high-volume flooding—strategic reconnaissance that often precedes more sophisticated compromise attempts. The nine-month reporting window demonstrates persistent rather than opportunistic threat behavior, with the address maintaining its malicious profile continuously across this period.
Hacking activity in threat-intelligence classification encompasses intrusion attempts, exploitation of software vulnerabilities, and unauthorized access campaigns against exposed services such as SSH, RDP, HTTP interfaces, and database ports. The concrete risk posed by an address with this profile is that any internet-facing service with weak authentication, unpatched software, or misconfigured access controls becomes a potential entry point for credential theft, data exfiltration, or lateral movement within a network. Operators of infrastructure like AS135377 are frequently associated with deliberate accommodation of such activity, meaning blocking this address represents a proportionate defensive measure rather than collateral filtering.
Site operators should implement immediate blocking of IP 152.32.206.87 at the network perimeter firewall or web application firewall layer, as the sustained threat history confirms ongoing risk. Rate-limiting authentication endpoints and enforcing strong password policies with multi-factor authentication significantly reduce the effectiveness of any intrusion attempts this address may conduct. Deploying intrusion detection systems and monitoring for connection attempts from this address aids in early threat identification. Keeping all exposed services patched and current eliminates the vulnerabilities that addresses in this category typically exploit during scanning campaigns.