Maximum Danger
IP 78.128.113.46 is a high-risk address operated by Miti 2000 EOOD in Bulgaria that has generated 1209 abuse reports and poses a severe threat to any exposed network service, with automated honeypot sensors flagging persistent hacking activity between April 2026 and August 2026 at a threat level of 10/10.
With a confidence score of 94% and an activity frequency rated 8/10, this Bulgarian IP has been extensively documented by 20 separate automated honeypot sensors over a five-month window. The volume of reports far exceeds typical noise levels seen across threat-intelligence feeds, indicating sustained and deliberate malicious behavior rather than incidental scanning. The underlying network is registered under ASN AS209160 to Miti 2000 EOOD, a Bulgarian entity, and the sustained pattern of detection across multiple independent sensor sources eliminates false-positive ambiguity from the dataset. The first reported activity appeared in April 2026, with consistent logging through August 2026, reflecting an extended campaign against target infrastructure.
The dominant threat classification assigned to this IP is Hacking, encompassing unauthorized access attempts, vulnerability exploitation, and intrusion activity against exposed services. A Suricata alert was triggered by ICMP Destination Unreachable traffic where the destination host communicated administrative prohibition, a technique often employed by adversaries conducting network reconnaissance, firewall probing, or using ICMP as a covert channel. The concrete real-world risk involves adversaries attempting to map network perimeters, identify open ports or services, and exploit configuration weaknesses or unpatched vulnerabilities to gain initial foothold within a target environment.
Site operators should block or aggressively rate-limit traffic originating from 78.128.113.46 at the network edge firewall and implement fail2ban or equivalent dynamic deny-listing tools to automate this response. Systems must be kept fully patched, with particular attention to services exposed to the internet, and intrusion detection rules should flag any further probes from this address. Enforcing strong authentication, limiting exposed services, and monitoring logs for follow-on credential-guessing or exploitation attempts are critical defensive measures that directly counter the attack patterns observed from this source.