Elevated Risk
IP 93.152.208.38 is a high-risk Bulgarian address associated with sustained hacking activity, accumulating 1,419 abuse reports across automated honeypot sensors between May and August 2026 at a notably high activity frequency rating of 8 out of 10. With a threat level score of 8/10 and a 94% confidence rating, the evidence base supporting malicious intent is exceptionally strong, making this IP a clear candidate for immediate blocking or strict access controls on any exposed services.
The aggregate data indicates persistent, repeated intrusion attempts rather than isolated scanning, with all 20 most recent reports consistently categorizing the activity as hacking. The IP originates from Bulgarian network infrastructure operated by Alferov Aleksey Aleksandrovich under ASN AS211486. The concentrated report volume over a four-month observation window, combined with exclusively honeypot-sourced detections, points to an active threat actor conducting sustained automated attacks against publicly accessible systems. The high confidence score of 94% reflects the clarity and consistency of the hostile activity patterns captured by detection infrastructure.
Hacking activity in this context encompasses unauthorized access attempts, exploitation attempts against vulnerable services, and general intrusion probing. The persistent nature of the reports from this address suggests the operator is running automated attack tools that systematically target exposed entry points such as authentication portals, remote administration interfaces, and network services. Any service accessible from the internet, particularly those using default or weak credentials, faces significant risk of compromise when accessed by this IP without defensive controls in place.
Network defenders should implement immediate blocking of inbound connections from 93.152.208.38 at the firewall or network edge, supplemented by automated dynamic blocking mechanisms such as fail2ban to respond to repeated hostile attempts in real time. Organizations should enforce strong authentication policies, disable unnecessary services on internet-facing hosts, maintain rigorous patching cycles, and deploy intrusion detection systems to alert on the distinctive connection patterns associated with this source. Regular review of authentication logs for sources matching this IP range will help identify any successful compromise attempts that may have occurred.