Critical Alert
IP 77.222.99.142 is a critical-risk address originating from Russia, operated by Intersvyaz-2 JSC, with a confirmed history of automated intrusion activity detected across multiple honeypot sensors. With 478 abuse reports filed against this single IP and a threat level of 10 out of 10, the address represents an aggressive and persistent threat actor. The overwhelming majority of recent reports categorise the activity as general hacking attempts, complemented by specific SSH brute-force patterns observed in honeypot environments. Detection data sourced from 20 independent automated honeypot sensors confirms the breadth and consistency of this malicious behaviour.
Analysis of the submitted detection data reveals that the activity is concentrated within October 2025, with both first and last reported dates falling within this window, indicating a focused and time-bounded campaign rather than sporadic scanning. Despite the extremely high report volume, the activity frequency metric registers at 0 out of 10, which may reflect that the IP is not currently executing live attacks at the moment of this assessment — however, the accumulated evidence of 478 separate incidents makes clear that this address has been extensively weaponised in the past. The 66% confidence score acknowledges that attribution to specific threat actors remains uncertain, though the pattern of behaviour is unambiguous. The AS8369 network allocation to Intersvyaz-2 JSC places the origin infrastructure within a Russian telecommunications provider, consistent with the geographic tag.
The dominant threat category, hacking activity with specific SSH brute-force indicators, represents one of the most common and damaging vectors targeting publicly exposed Linux servers and network appliances. SSH brute-force attacks systematically attempt to guess credentials by cycling through username and password combinations, exploiting weak or default credentials on exposed SSH daemons. When successful, these attacks grant attackers persistent remote access, enabling data exfiltration, cryptomining, lateral movement within networks, or the deployment of secondary payloads. The automated honeypot detections confirm that 77.222.99.142 actively participates in such campaigns at scale, posing a direct and concrete risk to any internet-facing SSH service that accepts password-based authentication.