High Risk
IP 165.154.134.152 is a critical-risk address classified at threat level 10/10, linked to sustained hacking activity, reconnaissance scanning, and evidence that the host itself may be compromised and weaponized. The IP has accumulated 218 total abuse reports over a six-month window spanning January to June 2026, with activity detected across 20 separate automated honeypot sensors. The dominant threat category is general hacking activity, accounting for 19 recent reports, while single reports flag it as an exploited host and a port scanning source respectively. With a confidence score of 74%, analysts assess this address presents a genuine, active danger to any exposed network infrastructure.
The network carrying this activity belongs to AS135377, operated by UCLOUD INFORMATION TECHNOLOGY HK LIMITED. Despite the IP's geolocation resolving to the United States, the ASN operator's registration in Hong Kong reflects a common pattern in cloud and infrastructure hosting where physical presence and corporate registration do not align. Suricata alerts tied to this address include protocol detection anomalies indicating malware or exploit payload transfer, as well as bidirectional protocol mismatches consistent with covert attack tooling. CiscoASA sensors additionally flagged this IP for port scanning and probing behavior, establishing that it is actively performing reconnaissance against target networks to identify exploitable services.
The prevalence of hacking activity alongside exploited-host classification suggests IP 165.154.134.152 functions both as an attack platform and potentially as a victim system repurposed by threat actors without the owner's knowledge. Port scanning activity indicates the IP is conducting systematic reconnaissance to map vulnerable entry points before launching intrusion attempts. The sustained report volume over six months demonstrates persistent, ongoing operation rather than opportunistic or brief malicious bursts, raising the probability that blocking this address will reduce exposure to credential attacks, vulnerability exploitation attempts, or coordinated scanning campaigns.
Network defenders should immediately block IP 165.154.134.152 at the firewall level and implement geolocation or ASN-based blocking as a supplementary layer. Rate-limiting and account-lockout policies on exposed services such as SSH, RDP, and web authentication portals will reduce the effectiveness of any intrusion attempts originating from this source. Deploying tools such as fail2ban or equivalent log-analysis utilities to parse honeypot and firewall logs will identify and auto-block repeated connection patterns associated with this threat actor. Organizations running publicly accessible services should review access logs for any interaction with this address and consider notifying the hosting provider to report suspected compromise of their infrastructure.