IP-Adresse

181.115.147.5

IPv4 Öffentlich
BO BO
AS6568
EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD...
185 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
10/10 Bedrohung
78% Selbstvertrauen
185 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 5% Most Dangerous
BO
BO Standort
EMPRESA NACIONAL DE TELEC... ASN 6568
185 Reports
Honeypot Datenquelle

Extreme Threat

IP 181.115.147.5, registered to EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA in Bolivia and operating on ASN AS6568, presents a maximum threat level of 10/10 and is definitively associated with persistent SSH brute-force attack campaigns. With 180 independent abuse reports across a seven-month window spanning November 2025 through May 2026, this address represents one of the most consistently reported sources of credential-compromise activity observed in recent regional threat telemetry. A confidence score of 81% grounds this assessment in substantial forensic data, while 20 separate automated honeypot sensor sources across the community have independently flagged this IP, confirming that the activity is neither isolated nor accidental.

The overwhelming majority of reports — 18 of the 24 categorized incidents — document SSH brute-force attempts, with additional activity classified as general hacking intrusion probes (4 reports) and confirmed exploited-host behaviour (2 reports). Sensor logs recorded multiple Fail2ban triggers across different observation windows, documenting 25, 30 and 10 individual SSH brute-force violations respectively, indicating sustained and repeated access attempts rather than opportunistic scanning. The detection timeline reveals continuous engagement over roughly half a year, placing the activity frequency at 4/10, which reflects persistent rather than sporadic behaviour. The presence of exploited-host indicators alongside active attack signatures suggests that the originating system may itself be compromised and operating under an external actor's control, compounding the threat profile.

SSH brute-force attacks systematically cycle through username and password combinations to guess server credentials, exploiting weak or default passwords to gain unauthenticated shell access to exposed Linux and network infrastructure. Successful compromise grants an attacker a fully privileged entry point into the target environment, enabling data exfiltration, lateral movement across internal networks, cryptomining deployment or further exploitation as a relay node. The repeated Fail2ban violations logged against this IP confirm that it is operating at volume against live SSH services, and the Suricata session-progress alerts indicate that connections are being maintained long enough to suggest active authentication attempts rather than simple port scanning. For any organisation exposing SSH to the internet, this IP represents a concrete, active credential-guessing threat requiring immediate defensive action.

Bedrohlicher als „95“ % der überwachten IP-Adressen

Threat Categories

SSH 28
Hacking 4
Exploited Host 2

Technische Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Empfohlene Abhilfemaßnahmen

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 6568) with generally good reputation. The ISP EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Continue monitoring for emerging patterns.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 3/10 Low
Confidence Score 66% High Confidence

Confidence History

9. März 2026 - 27. Juni 2026
78% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
Exploited Host Honeypot 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
Exploited Host Honeypot 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
181.115.147.5
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class B

Geolokalisierung

Land
BO BO
ASN
AS6568
ISP
EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA

DNS-Informationen

Reverse DNS
correo.oruro.gob.bo
PTR-Eintrag
Ja
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
185
Erstmals gemeldet
29 Nov. 2025
Zuletzt gemeldet
27 Juni 2026, 10:22

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS6568
EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA
BO BO

Bewertung von Netzwerkbedrohungen

1/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

37
Gesamtzahl der überwachten IP-Adressen
531
Gesamtzahl der Reports
14.4
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA (AS 6568), das in unserem Überwachungssystem 37 IP-Adressen verwaltet. Von diesen wurden 531 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 1 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

95 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 95 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.594

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 185 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 72 im ASN 6568

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 6,3 ++
Gesamtzahl der Reports 185 Netzwerk-Durchschnitt: 10 ++
Der Netzwerk-EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA hat eine Gesamtbedrohungsstufe von 1 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 212 in BO

Gefahrenstufe 10/10 Landesdurchschnitt: 6,1 ++
Gesamtzahl der Reports 185 Landesdurchschnitt: 9 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
8.8/10 Durchschnittliche Bedrohung
63% Durchschnittliche Konfidenz
18 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert
181.115.146.26 10/10
Selbstvertrauen 98%
Reports 20
Standort BO BO
181.115.231.212 10/10
Selbstvertrauen 94%
Reports 25
Standort BO BO
190.129.122.185 10/10
Selbstvertrauen 89%
Reports 113
Standort BO BO
190.129.122.12 10/10
Selbstvertrauen 86%
Reports 108
Standort BO BO
181.115.186.122 10/10
Selbstvertrauen 76%
Reports 14
Standort BO BO
181.115.157.136 10/10
Selbstvertrauen 72%
Reports 30
Standort BO BO
181.115.146.106 10/10
Selbstvertrauen 70%
Reports 13
Standort BO BO
190.129.54.194 10/10
Selbstvertrauen 62%
Reports 35
Standort BO BO
190.129.65.2 10/10
Selbstvertrauen 62%
Reports 14
Standort BO BO
181.115.192.10 10/10
Selbstvertrauen 60%
Reports 5
Standort BO BO
181.115.207.12 10/10
Selbstvertrauen 57%
Reports 6
Standort BO BO
181.115.200.84 10/10
Selbstvertrauen 56%
Reports 10
Standort BO BO
200.87.26.157 10/10
Selbstvertrauen 56%
Reports 7
Standort BO BO
200.87.90.187 10/10
Selbstvertrauen 51%
Reports 3
Standort BO BO
181.115.184.182 0/10
Selbstvertrauen 47%
Reports 3
Standort BO BO
181.115.180.242 0/10
Selbstvertrauen 47%
Reports 3
Standort BO BO
181.115.171.90 8/10
Selbstvertrauen 46%
Reports 3
Standort BO BO
181.115.207.172 10/10
Selbstvertrauen 42%
Reports 3
Standort BO BO
200.87.27.59 10/10
Selbstvertrauen 41%
Reports 3
Standort BO BO
181.115.196.162 8/10
Selbstvertrauen 40%
Reports 3
Standort BO BO

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
10/10 Durchschnittliche Bedrohung
92% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "181.115.147.5",
    "threat_level": 10,
    "confidence_score": 78,
    "total_reports": 185,
    "country_code": "BO",
    "isp_name": "EMPRESA NACIONAL DE TELECOMUNICACIONES SOCIEDAD ANONIMA",
    "asn": "6568",
    "first_reported": "2025-11-29 05:20:27",
    "last_reported": "2026-06-27 10:22:35",
    "exported_at": "2026-08-06T22:23:40+02:00",
    "source": "https://reportedip.com/ip/181.115.147.5/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.