Critical Threat
IP address 80.87.206.194, allocated to OVH SAS under ASN AS16276 and geolocated to Russia, presents a maximum threat level of 10/10 based on 261 total abuse reports filed between August 2025 and March 2026. Despite a modest activity frequency score of 0/10, the sustained volume of reports from automated honeypot sensors over a seven-month period signals an active, persistent threat operator with a focused interest in compromising remote access infrastructure. SSH-based attacks dominate the reported activity, accounting for the majority of recent threat categorisations alongside broader hacking probes and a smaller subset of exploited-host indicators.
The detection data reveals a clear pattern: honeypot sensors repeatedly captured SSH brute-force attempts and ongoing SSH sessions on expected ports, confirmed through Suricata intrusion-detection signatures categorised as informational alerts. This behavior is consistent with automated credential-stuffing campaigns targeting exposed Secure Shell services. The co-presence of exploited-host signals alongside active brute-force activity suggests the address may be used both for launching attacks and potentially for command-and-control relay, though the lower confidence score of 65% warrants treating the precise exploitation stage as partially unconfirmed. OVH SAS, a major European hosting provider, is a well-documented platform for both legitimate workloads and abuse due to its high-volume, low-cost infrastructure model.
SSH brute-force attacks represent a concrete, high-severity risk to any internet-facing server with password-authenticated Secure Shell exposed on standard or predictable ports. An attacker using automated tooling can cycle through credential combinations at speed, exploiting weak or default passwords to gain unauthorized shell access. Once inside, a threat actor can pivot to data exfiltration, lateral movement within a network, or deploying secondary payloads. The real-world danger lies not in sophistication but in sheer exposure: any unhardened SSH endpoint will be scanned and attacked relentlessly, and a successful compromise can grant a foothold equivalent to an insider with full system control.