Notable Threat
IP address 172.236.228.198, allocated to Akamai Connected Cloud under ASN AS63949 in the United States, presents a high-risk threat profile with a threat level of 8/10, supported by 216 total abuse reports from 20 distinct automated honeypot sensors over a monitoring period spanning August 2025 through June 2026.
The dominant threat activity identified against this address is general hacking intrusion attempts, accounting for 18 of the reported incidents, complemented by SSH brute-force probing, web application reconnaissance and a CiscoASA port scan signature. The activity frequency score of 6/10 indicates persistent rather than sporadic engagement with target infrastructure. Detection data confirms Suricata intrusion-prevention alerts specifically matched the SSH brute-force pattern, while separate honeypot events logged web application probing activity and port-scan signatures consistent with pre-attack reconnaissance. The 72% confidence score reflects a substantial but not absolute attribution certainty typical of cloud-allocated infrastructure where IPs may be repurposed across customer workloads.
SSH brute-force attacks represent a concrete credential-guessing threat targeting exposed Secure Shell services, with successful compromise enabling unauthenticated remote server access, lateral movement within networks and potential data exfiltration. Port scanning activity preceding such attempts signals methodical reconnaissance to identify accessible entry points before launching credential attacks. Web application probing further indicates interest in exploiting application-layer vulnerabilities in directly exposed web services.
Organizations exposing SSH services to this IP address should enforce key-based authentication exclusively, relocate the SSH daemon from port 22, disable direct root login and implement automated blocking tools such as fail2ban to throttle repeated authentication failures. Web application exposure should be mitigated through web application firewall deployment, routine security patching and monitoring for OWASP Top 10 exploitation patterns. Rate-limiting incoming connections from this address and similar cloud-sourced traffic provides an additional layer of defence against the scanning and brute-force activity pattern observed.