Maximum Danger
IP 182.93.50.90, registered in Macau and operated by Companhia de Telecomunicacoes de Macau SARL under ASN AS4609, is a critical-risk address associated with persistent SSH brute-force activity detected by automated honeypot sensors, with 164 abuse reports filed across 20 separate detection points over approximately five months.
Community and automated honeypot sensors logged the first reports concerning 182.93.50.90 in February 2026, with activity continuing through June 2026, indicating a sustained campaign rather than an isolated incident. The 88% confidence score and maximum 10/10 threat rating reflect the volume and consistency of detections, with the dominant threat category being SSH-based intrusion attempts, supplemented by broader hacking activity and exploited-host indicators. Fail2ban sensor data from multiple nodes recorded between 25 and 28 SSH brute-force violations per instance, while Suricata alerts confirmed active SSH sessions established on expected ports, suggesting successful authentication against some honeypot deployments. The 20 independent report sources across the detection network provide strong corroboration that this address is actively and persistently targeting secure-shell services.
SSH brute-force attacks represent one of the most common and effective initial-access vectors in network intrusions, where automated tooling systematically attempts credential combinations against exposed SSH daemons until access is granted. The detection of established SSH sessions and exploited-host status on 182.93.50.90 indicates that this address has successfully authenticated against some targets, potentially granting attackers command-line access to servers, internal network pivoting opportunities, and the ability to deploy further payloads. The sustained frequency and volume of attempts over multiple months demonstrates a deliberate, organized campaign rather than opportunistic scanning.
Operators exposing SSH services to the internet should immediately block 182.93.50.90 at the network perimeter firewall. Enforce key-based authentication exclusively and disable password-based SSH login to eliminate the attack vector entirely. Implementing tools such as fail2ban to automatically ban repeated authentication failure sources will further harden defenses. Regular monitoring of authentication logs for any connections originating from this address, combined with ensuring all SSH daemons are patched and run on non-default ports, will reduce exposure to credential-guessing campaigns of this nature.