IP-Adresse

163.7.8.178

IPv4 Öffentlich
ID ID
AS150436
Byteplus Pte. Ltd.
292 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
10/10 Bedrohung
88% Selbstvertrauen
292 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 5% Most Dangerous
ID
ID Standort
Byteplus Pte. Ltd. ASN 150436
292 Reports
Honeypot Datenquelle

Maximum Danger

IP 163.7.8.178 is a high-risk address originating from Indonesia with a threat level of 10/10, assessed with 94% confidence, and has accumulated 162 total abuse reports from automated honeypot sensors within a three-month window between March and May 2026.

The address resolves to Byteplus Pte. Ltd. operating autonomous system AS150436 and has demonstrated sustained malicious activity at a frequency rated 8/10. Detection data from twenty distinct honeypot sensors reveals a primary focus on SSH-related intrusion, with Suricata alerts confirming active SSH sessions in progress alongside documented brute-force authentication attempts against expected SSH ports. The report distribution spans Hacking (19 reports), SSH (12 reports), and Exploited Host (3 reports), indicating this IP is actively conducting credential-guessing campaigns against exposed SSH services while also exhibiting patterns consistent with a compromised or maliciously operated host within the Byteplus network.

SSH brute-force attacks represent a significant threat to any internet-exposed Linux or Unix servers listening on the default SSH port. Attackers systematically attempt common username/password combinations to gain unauthorized shell access, potentially achieving full system compromise, data exfiltration, or recruitment into botnets. The Suricata signatures indicating an active SSH session in progress combined with brute-force attempt reports suggest this IP is persistently probing target systems until access is obtained, making immediate blocking essential for any organization running accessible SSH endpoints.

Site operators should block 163.7.8.178 at the network perimeter immediately and implement fail2ban or equivalent intrusion-prevention tools to automatically ban repeated authentication failures. Hardening SSH configurations by disabling root login, enforcing key-based authentication over passwords, and changing the default port will substantially reduce exposure. Continuous monitoring of authentication logs for source IP 163.7.8.178 and regular review of honeypot abuse feeds will help maintain situational awareness regarding this persistent threat actor within the Byteplus AS150436 network.

Bedrohlicher als „97“ % der überwachten IP-Adressen

Threat Categories

Hacking 27
SSH 18
Exploited Host 7

Technische Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Empfohlene Abhilfemaßnahmen

Keep systems patched, implement intrusion detection, and follow security best practices.

Verhaltensanalyse

Aktivitätsmuster: Consistent Activity

Steady malicious activity over 4 weeks indicates persistent threat actor operations.

Erstmals beobachtet 8. Juli 2026
Letzte Aktivität 6. August 2026
Aktuell (7 Tage) 16 Vorfälle

Reputable Network

This IP is hosted on a network (ASN 150436) with generally good reputation. The ISP Byteplus Pte. Ltd. maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Long-term blocking recommended.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 8/10 High
Confidence Score 88% Verified

Confidence History

18. Juli 2026 - 6. Aug. 2026
88% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Neu Hacking SSH Honeypot x2 75%
Neu Hacking SSH Honeypot x2 75%
Neu Hacking Exploited Host Honeypot x2 75%
Neu SSH Honeypot 75%
Neu Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%

Technische Details

Grundlegende Informationen

IP-Adresse
163.7.8.178
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class B

Geolokalisierung

Land
ID ID
ASN
AS150436
ISP
Byteplus Pte. Ltd.

DNS-Informationen

Reverse DNS
Keine
PTR-Eintrag
Nein
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
292
Erstmals gemeldet
28 März 2026
Zuletzt gemeldet
6 Aug. 2026, 15:00

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS150436
Byteplus Pte. Ltd.
SG SG

Bewertung von Netzwerkbedrohungen

2/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

202
Gesamtzahl der überwachten IP-Adressen
6,091
Gesamtzahl der Reports
30.2
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu Byteplus Pte. Ltd. (AS 150436), das in unserem Überwachungssystem 202 IP-Adressen verwaltet. Von diesen wurden 6,091 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 2 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

97 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 97 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.024

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 292 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 258 im ASN 150436

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 8,3 +
Gesamtzahl der Reports 292 Netzwerk-Durchschnitt: 28 ++
Der Netzwerk-Byteplus Pte. Ltd. hat eine Gesamtbedrohungsstufe von 2 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 8.403 in ID

Gefahrenstufe 10/10 Landesdurchschnitt: 6,0 ++
Gesamtzahl der Reports 292 Landesdurchschnitt: 12 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.628 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.591 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.774 22.5%
  2. 02
    IN
    India IN
    49.096 16.8%
  3. 03
    CN
    China CN
    35.621 12.2%
  4. 04
    BR
    Brazil BR
    15.554 5.3%
  5. 05
    DE
    Germany DE
    10.499 3.6%
  6. 06
    PK
    Pakistan PK
    8.474 2.9%
  7. 07
    ID
    Indonesia ID DIESE IP-ADRESSE
    8.403 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.393 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
9.7/10 Durchschnittliche Bedrohung
99% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert
45.78.194.186 10/10
Selbstvertrauen 100%
Reports 71
Standort SG SG
163.7.9.84 10/10
Selbstvertrauen 100%
Reports 59
Standort ID ID
101.47.158.56 10/10
Selbstvertrauen 100%
Reports 54
Standort SG SG
163.7.9.55 10/10
Selbstvertrauen 100%
Reports 47
Standort ID ID
45.78.201.248 8/10
Selbstvertrauen 100%
Reports 42
Standort SG SG
150.5.154.160 10/10
Selbstvertrauen 100%
Reports 37
Standort HK HK
163.7.11.230 8/10
Selbstvertrauen 100%
Reports 36
Standort ID ID
163.7.3.154 10/10
Selbstvertrauen 100%
Reports 25
Standort ID ID
101.47.27.73 10/10
Selbstvertrauen 100%
Reports 23
Standort SG SG
150.5.141.198 10/10
Selbstvertrauen 100%
Reports 23
Standort HK HK
163.7.6.114 10/10
Selbstvertrauen 100%
Reports 15
Standort ID ID
163.7.4.169 10/10
Selbstvertrauen 99%
Reports 51
Standort ID ID
101.47.142.192 8/10
Selbstvertrauen 99%
Reports 17
Standort SG SG
45.78.206.111 10/10
Selbstvertrauen 98%
Reports 62
Standort SG SG
163.7.6.74 10/10
Selbstvertrauen 98%
Reports 33
Standort ID ID
101.47.15.26 10/10
Selbstvertrauen 98%
Reports 29
Standort SG SG
101.47.155.9 10/10
Selbstvertrauen 98%
Reports 27
Standort SG SG
163.7.11.155 10/10
Selbstvertrauen 98%
Reports 17
Standort ID ID
69.5.7.218 10/10
Selbstvertrauen 98%
Reports 14
Standort ID ID
45.78.235.96 10/10
Selbstvertrauen 98%
Reports 13
Standort SG SG

IP-Adressen aus demselben Subnetzbereich, vermutlich aus demselben Netzwerksegment.

3 Verwandte IPs
3.3/10 Durchschnittliche Bedrohung
66% Durchschnittliche Konfidenz
1 Hohe Bedrohung
Erhöhtes Risiko: Mehrere miteinander in Zusammenhang stehende IP-Adressen werden markiert

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
9.3/10 Durchschnittliche Bedrohung
100% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "163.7.8.178",
    "threat_level": 10,
    "confidence_score": 88,
    "total_reports": 292,
    "country_code": "ID",
    "isp_name": "Byteplus Pte. Ltd.",
    "asn": "150436",
    "first_reported": "2026-03-28 23:20:12",
    "last_reported": "2026-08-06 15:00:14",
    "exported_at": "2026-08-06T15:11:56+02:00",
    "source": "https://reportedip.com/ip/163.7.8.178/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.