IP address 27.254.152.90 has been flagged in 353 abuse reports across 23 independent threat intelligence sources, resulting in a threat score of 100.0/100 (critical risk). The primary activity associated with this IP is aggregated threat, along with attacks, brute force, bruteforce, malware c2, scanning, severe abuse, ssh-bruteforce, ssh brute force, ssh bruteforce, unknown, voip attack, web attack, web brute force.
This IP is geolocated in Thailand and belongs to the network dragonhispeed (AS63940). Reports span from 2025-09-10 to 2026-03-16.
Assessment: With 353 abuse reports, 27.254.152.90 shows persistent malicious activity that has been flagged by multiple threat intelligence feeds. The IP has been observed conducting automated SSH login attempts against internet-facing servers, a technique commonly used to gain unauthorized access to systems.