Substantial Risk
IP address 199.45.155.107 is a maximum-threat-level address assessed at 10/10 that has generated 232 abuse reports from automated honeypot sensors over approximately nine months, indicating persistent and aggressive intrusion activity originating from a US-based network operator. The confidence score of 73% combined with 20 independent sensor detections across the timeframe from October 2025 through June 2026 establishes a reliable threat profile dominated by general hacking activity alongside secondary exploitation and IoT targeting indicators.
The volume and consistency of reports position this address firmly within the highest-risk category for network defenders, particularly given the concrete detection of active attack connection patterns, documented malware and exploit-related activity, and confirmed IoT and industrial control system targeting. The Suricata alert flagging an SSH session in progress on an expected port further corroborates that this actor is actively conducting brute-force or credential-based intrusion attempts against exposed SSH services. The simultaneous presence of exploited host signals suggests the infrastructure may itself be compromised or operating under attacker control, compounding the risk to any exposed services.
The dominant hacking classification encompasses a broad spectrum of intrusion techniques including vulnerability exploitation, unauthorized access attempts, and sustained attack campaigns against target systems. For organizations running publicly accessible services, especially SSH daemons, this activity represents a direct pathway to account compromise, lateral movement, and data exfiltration if successful. The IoT targeting component raises additional concerns for defenders managing connected device fleets, as successful exploitation could grant attackers persistent network access or pivot points.
Immediate defensive measures should include blocking or rate-limiting this address at the network perimeter, enforcing strong authentication and key-based SSH access where possible, and deploying intrusion detection rules to alert on similar scanning patterns. Operators are advised to review authentication logs for suspicious login attempts, implement fail2ban or equivalent account lockout policies, and ensure all exposed services follow current patch and hardening guidelines. Organizations discovering compromise should consider notifying the upstream provider associated with AS398722 regarding the potential compromised infrastructure.