Critical Threat
185.213.175.140 is a maximum-threat address originating from Spain, linked to SSH brute-force attacks with a 10/10 threat score and 284 total abuse reports spanning November 2025 to April 2026.
The IP is registered to NextGenWebs, S.L. operating under AS41608, and has been consistently flagged by automated honeypot sensors over a six-month observation window. Analysis of reported threat data identifies SSH as the sole attack category, with fail2ban sensors recording 25 violations attributable to credential-guessing activity. While the activity frequency score is rated low, the sustained volume of abuse reports and maximum threat classification indicate persistent scanning behaviour directed at exposed SSH services.
SSH brute-force attacks represent a prevalent initial-access vector where automated tools systematically attempt server authentication using common username/password combinations. The real-world risk includes complete server compromise, lateral movement within networks, data exfiltration, and deployment of secondary payloads such as cryptocurrency miners or ransomware. The sustained nature of the activity against this IP suggests it forms part of a coordinated scanning campaign rather than isolated probing.
Site operators should immediately audit SSH exposure by restricting access to known IP ranges, enforcing key-based authentication exclusively, and relocating the SSH daemon from its default port to reduce automated discovery. Deploying fail2ban to dynamically block repeated authentication failures provides an additional automated defence layer. Disabling direct root login and enforcing strong password policies eliminate common attack pathways. Continuous network monitoring for unusual authentication patterns from this address and similar sources will support early detection of compromise attempts.