Severe Risk
IP 78.128.112.30 is a critical-risk address linked to high-volume hacking activity, with automated honeypot sensors recording 1,153 abuse reports and a threat level rating of 10 out of 10.
Operating from Bulgarian network infrastructure AS208637 (4 Vendeta Ltd), this IP demonstrated sustained malicious behavior across a five-month window from April 2026 through August 2026. The activity frequency rating of 8 out of 10 and the 94% confidence score indicate consistent, highly reliable detection by twenty separate honeypot sensors. The abuse volume of 1,153 reports represents concentrated hostile activity rather than scattered noise, placing this address among the most actively abused within Bulgarian address space.
The dominant threat classification centers on general hacking activity encompassing intrusion attempts, vulnerability exploitation and unauthorized access efforts. Additionally, honeypot sensors detected ICMP communications flagged by Suricata rules, specifically destination unreachable messages indicating administratively prohibited contact attempts. This pattern suggests the IP is actively probing network infrastructure with scanning and enumeration tools, attempting to identify vulnerable services for potential compromise.
Network defenders should immediately block or rate-limit traffic from 78.128.112.30 at the perimeter firewall and implement automated banning tools such as fail2ban to mitigate repeated intrusion attempts. Ensuring all systems remain current with security patches eliminates entry points that such hacking activity targets. Activating intrusion detection systems to generate alerts on similar communication patterns provides early warning of follow-up attempts from this or related infrastructure.