Extreme Threat
IP 185.233.3.95 is a critical-risk address operated by Enterprise Cloud Ltd. in Kazakhstan that has generated 194 abuse reports and is actively engaged in SSH brute-force attacks against remote servers. With a threat level scored at 10 out of 10 and a confidence rating of 80 percent, this IP represents a persistent, automated threat to publicly accessible SSH services worldwide. The overwhelming majority of recent reports identify it as a source of SSH authentication attacks, indicating a deliberate, focused campaign rather than opportunistic scanning.
Detection data from 20 automated honeypot sensors reveals a sustained campaign spanning November 2025 through May 2026, with multiple independent sources documenting repeated SSH brute-force attempts. Specific honeypot logs recorded 31, 25, and 27 violations respectively attributed to automated SSH authentication attacks within short succession. Suricata alert signatures further confirmed active SSH sessions in progress on standard expected ports, corroborating the brute-force activity captured by fail2ban filters. The network is registered to AS48096 under Enterprise Cloud Ltd., a Kazakhstan-based hosting operator, placing the origin in a Central Asian data center environment.
The dominant threat category associated with IP 185.233.3.95 is SSH brute-forcing, a high-volume automated technique that systematically attempts credential combinations against exposed SSH daemons. This attack pattern poses a direct risk to any server with password-based authentication enabled on standard ports, particularly those using weak or default credentials. Additionally, the inclusion of "Exploited Host" in recent reports suggests this IP may itself be running on a compromised server, meaning the originating system has been taken over by threat actors and is now being weaponised without the legitimate operator's knowledge. The concrete risk to an exposed service is unauthorised server access, data exfiltration, lateral movement across internal networks, and potential deployment of secondary malware or ransomware.
Site operators should treat IP 185.233.3.95 as hostile and block all inbound SSH connections from this address at the network perimeter. Deploy fail2ban or equivalent intrusion-prevention tooling to automatically ban source IPs after a configurable threshold of failed authentication attempts, significantly reducing the success rate of credential-guessing campaigns. Migrate SSH access to non-standard ports and enforce public-key authentication exclusively, eliminating the password-guessing attack surface entirely. Finally, disable direct root or administrative login over SSH and maintain a strict allowlist of permitted source IPs for privileged access. Operators who discover this IP targeting their infrastructure should also consider notifying Enterprise Cloud Ltd. to report potential compromise of their customer infrastructure.