Maximum Danger
IP 78.128.112.74 is a critical-risk address operated by 4 Vendeta Ltd under ASN AS208637 in Bulgaria, associated with sustained SSH brute-force and hacking activity across automated honeypot sensors and community abuse reports.
The address carries a maximum threat level of 10/10 and has accumulated 802 total abuse reports since its first appearance in September 2025 through March 2026, indicating persistent malicious behavior over approximately six months. Twenty distinct automated honeypot sensors detected this activity, logging 18 incidents classified as general hacking intrusion attempts and 3 specifically documenting SSH brute-force behavior. The 59% confidence score reflects the substantial volume of corroborating sensor data despite the relatively low recent activity frequency score, suggesting ongoing but intermittent engagement with target services.
The dominant threat category involves automated attempts to gain unauthorized server access by systematically guessing SSH credentials against exposed authentication interfaces. This pattern represents a concrete real-world risk because successful credential compromise grants attackers direct command-level access to systems, enabling data exfiltration, malware deployment or further network penetration. Even failed attempts strain server resources and generate security alerts that can mask more sophisticated intrusion activity, and the sustained volume of reports indicates this is not opportunistic scanning but deliberate, repeated targeting of vulnerable endpoints.
Site operators should immediately block or rate-limit connections from this address at the firewall level and audit SSH configurations to enforce key-based authentication in place of password-only methods, disable direct root login and change the default SSH port to reduce attack surface. Implementing automated abuse-detection tools such as fail2ban can dynamically block repeat offenders, and restricting SSH access to known whitelisted IP ranges eliminates opportunistic brute-force exposure entirely. Continuous monitoring of authentication logs for patterns consistent with brute-force activity will enable rapid response to any renewed engagement from this source.