Severe Risk
IP 198.24.79.245 is a critical-risk address originating from a Time Warner Cable residential network in the United States that has been linked to SSH brute-force intrusion attempts, accumulating 159 abuse reports from automated honeypot sensors across a concentrated August 2025 timeframe with a threat level assessment of 10 out of 10.
The detection profile shows 20 distinct automated honeypot sources reporting this IP, documenting 12 general hacking events and 8 specifically categorized as SSH authentication attacks. The 59% confidence score reflects uncertainty regarding the IP's long-term behavioral patterns, while the activity frequency metric of 0 out of 10 suggests the hostile behavior has been episodic rather than sustained. Operating through AS11426 (TWC-11426-CAROLINAS), this address represents a residential broadband connection used as an attack launch point, which is common in both compromised endpoint scenarios and threat actors leveraging residential infrastructure for anonymity.
SSH brute-force attacks represent a persistent threat to any internet-exposed Linux servers or network devices running the Secure Shell protocol. Attackers systematically attempt credential combinations to gain unauthorized server access, successfully compromising poorly secured deployments to establish persistent backdoors, deploy cryptocurrency miners or exfiltrate sensitive data. The volume of 159 reports indicates sustained, automated scanning behavior consistent with botnet-driven campaigns rather than isolated manual probing.
Site operators maintaining SSH-accessible servers should enforce key-based authentication exclusively, change the default port from 22, and implement automated abuse-prevention tools such as fail2ban to block repeated authentication failures. Network defenders should consider blocking or rate-limiting traffic from residential IP ranges observed conducting automated scanning, maintain strict password policies with lockout mechanisms, and monitor authentication logs for the distinctive pattern of rapid sequential login attempts originating from diverse source addresses.