Maximum Danger
IP 87.121.84.86 is a critical-risk address linked to sustained hacking activity, including unauthorized SSH session probes on non-standard ports, operated through Vpsvault.host Ltd (ASN AS215925) and detected by automated honeypot sensors since September 2025.
The IP has generated 299 total abuse reports over approximately eight months, with 20 of those specifically categorized as hacking attempts. Detection systems flagged Suricata alerts indicating SSH sessions being established on unusual ports — a common technique used to bypass basic firewall rules that only permit default SSH configurations. The geographic origin is the United States, while the ASN operator, Vpsvault.host Ltd, is a VPS hosting provider whose infrastructure is frequently leveraged for automated attack campaigns. With a threat level rated 10/10 and a 71% confidence score, the volume and persistence of these reports indicate persistent, systematic probing rather than isolated opportunistic scanning. The activity frequency of 3/10 suggests scripted or bot-driven behavior typical of automated exploitation toolkits.
The dominant threat category — hacking — encompasses a broad range of intrusion attempts, including vulnerability exploitation and unauthorized access probes. The specific attack pattern involving SSH sessions on unusual ports indicates the actor is actively attempting to evade standard authentication controls and reconnaissance detection. Real-world risk includes credential brute-forcing, exploitation of unpatched service vulnerabilities, and potential lateral movement if initial access is achieved. Services such as SSH, RDP, or any exposed management interfaces are directly endangered by this type of sustained probing.
Site operators should immediately block IP 87.121.84.86 at the firewall or network perimeter level and implement rate-limiting rules using tools such as fail2ban to automatically ban repeated connection attempts from this source. SSH access should be restricted to known whitelisted IP ranges, and non-standard SSH ports — if in use — should be audited and secured with certificate-based authentication alongside strong passwords. Keeping all exposed services patched and maintaining active intrusion detection monitoring will further reduce vulnerability to the automated exploitation techniques this IP represents.