IP-Adresse

203.110.233.225

IPv4 Öffentlich
CN CN
AS134756
CHINANET Nanjing Jishan IDC network
214 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
10/10 Bedrohung
73% Selbstvertrauen
214 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 10% High Threat
CN
CN Standort
CHINANET Nanjing Jishan I... ASN 134756
214 Reports
Gemischt Datenquelle

Critical Alert

IP 203.110.233.225 is a high-risk address originating from CHINANET Nanjing Jishan IDC network in China that has been linked to sustained SSH brute-force attacks and broader hacking activity, warranting immediate blocking on any exposed services. With 213 total abuse reports across a four-month window from February to June 2026 and a threat level of 10 out of 10, this IP represents a persistent intrusion threat despite its relatively low activity frequency score of 2 out of 10.

Automated honeypot sensors recorded the vast majority of detections with 18 reports, while community sources contributed an additional 2 reports. Analysis of reported threat categories reveals a clear focus on SSH-based attacks, accounting for 14 documented incidents, alongside 13 reports of general hacking activity and 2 brute-force related entries. Detection systems documented multiple SSH sessions being established on expected ports, indicating sustained engagement with target services rather than opportunistic scanning. The IP's assignment to an IDC network in Nanjing suggests the attacking infrastructure may be hosted on compromised servers or rented cloud resources commonly used in automated attack campaigns.

SSH brute-force attacks systematically test credential combinations against exposed servers, exploiting weak or default passwords to gain unauthorized access. Successful compromise typically leads to backdoor installation, cryptocurrency mining malware deployment, or lateral movement within compromised networks. The threat posed by this specific IP is elevated by confirmed evidence of active SSH sessions on expected ports, demonstrating persistent authentication probing rather than passive reconnaissance. Organizations running publicly accessible SSH services face direct risk of credential compromise if proper hardening measures are not implemented.

Site operators should immediately block this IP at the firewall level and implement key-based authentication exclusively for SSH access, eliminating password-based login vectors entirely. Deploying fail2ban to automatically ban IPs after repeated authentication failures provides an effective automated defence layer against brute-force attempts. Changing the default SSH port from 22 to a non-standard port significantly reduces exposure to automated scanning campaigns. Additionally, disabling root login and enforcing multi-factor authentication substantially raises the barrier for successful intrusion attempts.

Bedrohlicher als „94“ % der überwachten IP-Adressen

Threat Categories

Hacking 21
SSH 20
Brute-Force 2

Technische Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Empfohlene Abhilfemaßnahmen

Keep systems patched, implement intrusion detection, and follow security best practices.

Verhaltensanalyse

Aktivitätsmuster: Consistent Activity

Steady malicious activity over less than a day indicates persistent threat actor operations.

Erstmals beobachtet 31. Juli 2026
Letzte Aktivität 31. Juli 2026
Aktuell (7 Tage) 1 Vorfälle

Reputable Network

This IP is hosted on a network (ASN 134756) with generally good reputation. The ISP CHINANET Nanjing Jishan IDC network maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Long-term blocking recommended.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 2/10 Very Low
Confidence Score 71% High Confidence

Confidence History

30. März 2026 - 31. Juli 2026
73% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Hacking Honeypot 75%
SSH Honeypot 75%
Brute-Force Community 75%
Brute-Force Community 75%
Hacking Honeypot 75%
SSH Hacking Honeypot x2 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
203.110.233.225
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class C

Geolokalisierung

Land
CN CN
ASN
AS134756
ISP
CHINANET Nanjing Jishan IDC network

DNS-Informationen

Reverse DNS
Keine
PTR-Eintrag
Nein
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
214
Erstmals gemeldet
18 Feb. 2026
Zuletzt gemeldet
31 Juli 2026, 02:06

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS134756
CHINANET Nanjing Jishan IDC network
CN CN

Bewertung von Netzwerkbedrohungen

3/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

45
Gesamtzahl der überwachten IP-Adressen
1,073
Gesamtzahl der Reports
23.8
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu CHINANET Nanjing Jishan IDC network (AS 134756), das in unserem Überwachungssystem 45 IP-Adressen verwaltet. Von diesen wurden 1,073 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 3 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

94 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 94 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.571

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 214 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 72 im ASN 134756

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 6,9 +
Gesamtzahl der Reports 214 Netzwerk-Durchschnitt: 18 ++
Der Netzwerk-CHINANET Nanjing Jishan IDC network hat eine Gesamtbedrohungsstufe von 3 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 35.669 in CN

Gefahrenstufe 10/10 Landesdurchschnitt: 5,0 ++
Gesamtzahl der Reports 214 Landesdurchschnitt: 6 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN DIESE IP-ADRESSE
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
9/10 Durchschnittliche Bedrohung
80% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert
117.62.238.207 8/10
Selbstvertrauen 100%
Reports 35
Standort CN CN
220.154.133.230 10/10
Selbstvertrauen 94%
Reports 27
Standort CN CN
117.62.232.145 8/10
Selbstvertrauen 92%
Reports 51
Standort CN CN
117.62.235.38 8/10
Selbstvertrauen 92%
Reports 11
Standort CN CN
220.154.133.166 10/10
Selbstvertrauen 91%
Reports 17
Standort CN CN
121.229.202.143 10/10
Selbstvertrauen 89%
Reports 11
Standort CN CN
117.62.203.160 10/10
Selbstvertrauen 86%
Reports 60
Standort CN CN
117.62.235.52 8/10
Selbstvertrauen 84%
Reports 18
Standort CN CN
220.154.131.119 10/10
Selbstvertrauen 81%
Reports 6
Standort CN CN
220.154.131.136 10/10
Selbstvertrauen 78%
Reports 5
Standort CN CN
121.229.191.90 10/10
Selbstvertrauen 76%
Reports 32
Standort CN CN
117.62.237.45 8/10
Selbstvertrauen 76%
Reports 26
Standort CN CN
117.62.237.194 8/10
Selbstvertrauen 76%
Reports 17
Standort CN CN
180.110.149.157 10/10
Selbstvertrauen 75%
Reports 38
Standort CN CN
117.62.239.123 8/10
Selbstvertrauen 75%
Reports 12
Standort CN CN
117.62.234.21 8/10
Selbstvertrauen 71%
Reports 24
Standort CN CN
117.62.232.202 8/10
Selbstvertrauen 69%
Reports 7
Standort CN CN
49.65.99.4 8/10
Selbstvertrauen 67%
Reports 9
Standort CN CN
121.229.70.134 10/10
Selbstvertrauen 65%
Reports 518
Standort CN CN
220.154.131.138 10/10
Selbstvertrauen 65%
Reports 4
Standort CN CN

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
9.7/10 Durchschnittliche Bedrohung
100% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "203.110.233.225",
    "threat_level": 10,
    "confidence_score": 73,
    "total_reports": 214,
    "country_code": "CN",
    "isp_name": "CHINANET Nanjing Jishan IDC network",
    "asn": "134756",
    "first_reported": "2026-02-18 20:13:57",
    "last_reported": "2026-07-31 02:06:37",
    "exported_at": "2026-08-06T21:43:14+02:00",
    "source": "https://reportedip.com/ip/203.110.233.225/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.