Critical Threat
IP 92.118.39.92 is a critical-risk address associated with SSH brute-force intrusion attempts and confirmed exploited-host activity, amassing 483 abuse reports across automated honeypot sensors since December 2025. With a threat-level score of 10/10, this IP represents an active and persistent attack platform operating from US-based network infrastructure under AS47890 (Unmanaged Ltd), and its IP reputation among security databases is definitively negative.
The detection evidence is substantial and consistent across multiple sources. Of the 483 total abuse reports, recent submissions break down into Hacking attempts (16), SSH brute-force activity (15), and one confirmed Exploited Host classification. Suricata intrusion-detection signatures specifically documented SSH sessions observed on expected ports followed immediately by brute-force authentication attempts, indicating systematic credential-guessing campaigns in progress. Twenty separate automated honeypot sensors contributed reports spanning from December 2025 through April 2026, demonstrating broad and sustained detection coverage rather than isolated observations from a single source.
SSH brute-force attacks represent a high-volume attack vector where adversaries systematically cycle through username and password combinations to gain unauthorized server access. When an IP receives an Exploited Host classification, it signals that the underlying system itself has been compromised and is being weaponized as an unwitting attack platform, effectively operating under an attacker's control without the owner's knowledge. The observed pattern of SSH sessions followed by brute-force signatures indicates this address is actively conducting credential-stuffing operations targeting exposed SSH services worldwide, posing a direct threat to any publicly accessible SSH daemon.
Site operators should take immediate defensive action: block or aggressively rate-limit traffic from 92.118.39.92 at the network perimeter given the confirmed malicious status, enforce key-based SSH authentication and disable password-based login entirely to eliminate this attack surface, and deploy automated dynamic blocking tools such as fail2ban to detect and quarantine brute-force patterns in real time. Regularly reviewing authentication logs for failed login attempts from this address and implementing strict firewall rules governing inbound SSH access will further harden exposure against credential-guessing campaigns originating from this and similar compromised infrastructure.