Substantial Risk
IP 36.134.96.76 is a critical-risk address operated by China Mobile communications corporation (ASN AS56046) that has generated 378 abuse reports from 20 automated honeypot sensors across a six-month observation window, with hacking intrusion attempts representing the dominant threat vector and an associated threat level of 10 out of 10.
Network telemetry places this Chinese IP within AS56046, a large mobile carrier infrastructure block, and the cumulative abuse volume of 378 reports from a broad sensor network indicates sustained, multi-source detection over the period spanning September 2025 through February 2026. The report distribution across 20 independent honeypot sensors demonstrates that this address has been observed targeting a wide footprint of vulnerable entry points, while the confidence score of 63 percent reflects the challenge of fully attributing intent without additional forensic context. The specific attack-pattern indicators of "sshd on" detection and SSH command-input activity, combined with a general hacking classification in 18 of the 20 most recent categorized reports, point clearly toward unauthorized access attempts rather than reconnaissance alone.
The dominant hacking activity encompasses intrusion attempts, vulnerability exploitation and unauthorized access probes, with SSH brute-forceGuessing constituting a notable subset of observed behavior. This pattern means that exposed SSH services listening on standard ports face dictionary-based credential attacks designed to compromise server access. Even though the activity frequency metric appears minimal, the sheer report volume across distributed sensors confirms persistent targeting of internet-facing authentication interfaces. An attacker succeeding through such methods could obtain shell access, escalate privileges and deploy further payloads within a victim environment.
Site operators should immediately block or rate-limit traffic from this IP at the firewall or network edge, deploy fail2ban or equivalent rule engines to auto-ban repeated SSH authentication failures, and enforce key-based authentication with password authentication disabled on all internet-facing SSH daemons. Changing the default SSH listening port reduces automated scanning exposure, disabling root login over SSH eliminates a high-value target account, and maintaining comprehensive logging with active monitoring ensures rapid detection of any subsequent intrusion attempts from this or related addresses.