Severe Risk
IP 170.64.228.234 is a high-risk address associated with SSH brute-force attacks and broader hacking activity, detected across multiple automated honeypot sensors with a maximum threat rating of 10/10.
Analysis of reports from November 2025 shows 421 abuse reports attributed to this DigitalOcean-hosted IP address (AS14061, operating from Australian infrastructure), with 20 distinct honeypot sensors logging activity spanning SSH brute-force attempts and general intrusion vectors. The confidence score of 69% reflects the substantial volume of independent reports, though the activity frequency metric indicates attacks are concentrated in intermittent bursts rather than sustained traffic, suggesting automated scanning tools launching periodic campaigns against exposed SSH services.
SSH brute-force attacks systematically attempt to gain unauthorized server access by rapidly cycling through username and password combinations, exploiting weak or default credentials to compromise Linux servers and network devices. The concrete risk involves complete server takeover, data exfiltration, and use of compromised systems as launch pads for further attacks against other targets. With 421 independent reports logged across honeypot infrastructure in a single month, IP 170.64.228.234 represents an active, determined threat actor with enough infrastructure resources to sustain scanning operations.
Organizations with exposed SSH services should implement key-based authentication exclusively, disable password-based authentication entirely, move SSH from port 22 to a non-standard port, and configure fail2ban to automatically block repeated authentication failures. Regular monitoring of authentication logs and limiting SSH access to known IP ranges provide additional defensive layers against this type of automated threat.