Extreme Threat
187.62.87.27 is a high-risk IP address linked to sustained SSH brute-force attacks and confirmed exploitation activity, with a threat level of 10/10 based on 441 abuse reports from automated honeypot sensors. The address, originating from Brazil and operated by INFINITYGO TELECOM LTDA, was first reported in September 2025 and remains active through May 2026, indicating persistent malicious behavior over an extended period.
The IP has accumulated 441 total reports with an activity frequency rating of 8/10, sourced from 20 distinct automated honeypot sensors. Of the reported threat categories, SSH-related activity dominates with 19 instances, supplemented by 6 general hacking reports and 2 confirmed exploited host classifications. Fail2ban logs documented multiple high-volume SSH brute-force campaigns, with individual campaigns recording 25 to 32 violations each, and Suricata alerts confirmed active SSH sessions on expected ports, suggesting both successful authentication attempts and ongoing exploitation of compromised infrastructure.
SSH brute-force attacks represent one of the most prevalent and effective attack vectors targeting internet-facing servers. Attackers deploy automated tools that cycle through common username-password combinations, exploiting weak or default credentials to gain unauthorized access. The presence of Suricata alerts indicating established SSH sessions on expected ports, combined with the exploited host classification, suggests that 187.62.87.27 may itself be a compromised system weaponized by threat actors to conduct further intrusion campaigns. Successful compromise of a target server grants attackers persistent access, enabling data theft, malware deployment, lateral movement within networks, and use of the compromised host as a pivot point for additional attacks.
Site operators should immediately block 187.62.87.27 at the network perimeter and implement key-based SSH authentication to eliminate password-based authentication vectors entirely. Deploying fail2ban or similar intrusion prevention tools provides automated blocking of repeated connection attempts. Operators should also disable direct root login, change the default SSH listening port, and enforce account lockout policies after a limited number of failed authentication attempts. If this IP appears to be hosted by a legitimate service provider, consider filing an abuse report with INFINITYGO TELECOM LTDA to alert them to potential compromised infrastructure within their network.