Severe Risk
IP 165.154.36.107 is a high-risk address with a threat level of 10 out of 10 that has been linked to sustained hacking activity targeting exposed services, drawing 171 total abuse reports from automated honeypot sensors since September 2025.
The IP is registered to UCLOUD INFORMATION TECHNOLOGY HK LIMITED under ASN AS135377 and geolocates to the United States, representing a common operational pattern where threat actors utilise offshore cloud infrastructure to mask the true origin of malicious traffic. All 20 of the most recent reports classify the activity as hacking, which encompasses intrusion attempts, exploitation attempts and unauthorized access probing. Detection data indicates a moderate activity frequency of 3 out of 10, yet the consistent volume of community reports spanning approximately eight months demonstrates persistent rather than opportunistic targeting. The 75% confidence score reflects that while the threat profile is clear, attribution to a specific actor or campaign remains partially indeterminate.
Hacking activity of this nature typically involves automated scripts scanning for open ports, weak credentials or unpatched vulnerabilities in SSH, RDP, FTP and web-facing applications. Each successful connection attempt represents a potential entry point for data exfiltration, malware deployment or lateral movement within a network. With 171 total reports accumulated over multiple months, IP 165.154.36.107 has demonstrated a sustained, systematic approach to probing infrastructure rather than a transient scanning event.
Organisations exposing services to this IP should implement immediate defensive measures including blocking or rate-limiting at the network perimeter, enforcing strong multi-factor authentication on all remote access services, and deploying defensive tools such as fail2ban to automatically ban repeated offenders. Regular audit of authentication logs for brute-force patterns and maintenance of up-to-date intrusion detection signatures will further reduce exposure to the techniques this address is known to employ.