IP-Adresse

41.139.172.151

IPv4 Öffentlich
KE KE
AS37061
Safaricom
1.040 Reports
Diese IP-Adresse steht unter Beobachtung Verdächtige Aktivität festgestellt – bitte genau beobachten
10/10 Bedrohung
62% Selbstvertrauen
1.040 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 10% High Threat
KE
KE Standort
Safaricom ASN 37061
1.040 Reports
Honeypot Datenquelle

Critical Threat

IP 41.139.172.151 is a critical-risk address originating from Kenya and operated by Safaricom (AS37061) that has been flagged as a compromised system being weaponised for malicious activity, with 1039 independent abuse reports logged against it by automated honeypot sensors. The sheer volume of reports combined with an Exploited Host classification indicates that this IP has likely been taken over by threat actors and is now functioning as an unwitting attack platform, potentially distributing malware or participating in coordinated exploitation campaigns without the knowledge of its legitimate operator.

According to available data, all 1039 reports were generated within November 2025 through automated honeypot detection systems, suggesting concentrated hostile activity during that period. The dominant reported category—Exploited Host—appeared in 20 recent reports and signals that the host itself has been compromised rather than merely engaging in outbound scanning or brute-force attempts. Despite a confidence score of 59%, the consistency of reporting and the critical 10/10 threat designation indicate that network defenders should treat this address as actively dangerous. The very low current activity frequency score of 0/10 may suggest the malicious campaign has temporarily subsided, but exploited hosts frequently resume operation under new attacker control or remain compromised for future use.

The Exploited Host classification represents one of the most serious threat categories in IP reputation work because it signifies a system belonging to an innocent organisation or individual that has been subverted into an attack vector. Compromised hosts are frequently deployed to scan for vulnerabilities, distribute payloads, relay traffic to obscure attacker infrastructure, or launch attacks that evade traditional reputation-based blocking. Victims of such abuse often face reputation damage and potential upstream sanctions. For organisations with services exposed to this address, the risk is not merely nuisance traffic but potential interaction with malware-laced connections or exploitation attempts against vulnerable software.

Site operators should immediately block IP 41.139.172.151 at the network perimeter or firewall level given the critical threat designation and Exploited Host status. Implementing fail2ban or equivalent automated ban tools can detect and neutralise repeated connection attempts from compromised sources. Exposed services should be reviewed for unpatched vulnerabilities that an exploited host might attempt to leverage, with particular attention to web interfaces and remote access portals. Operators are encouraged to consider notifying Safaricom's abuse team to facilitate remediation of the compromised subscriber account. Continuous monitoring for inbound connections from this address, even after blocking, can serve as an early warning indicator if the threat actor shifts tactics or reactivates the host.

Bedrohlicher als „92“ % der überwachten IP-Adressen

Threat Categories

Exploited Host 30
Hacking 1

Technische Details

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Empfohlene Abhilfemaßnahmen

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Verhaltensanalyse

Aktivitätsmuster: Consistent Activity

Steady malicious activity over less than a day indicates persistent threat actor operations.

Erstmals beobachtet 23. Juli 2026
Letzte Aktivität 23. Juli 2026
Aktuell (7 Tage) 0 Vorfälle

Reputable Network

This IP is hosted on a network (ASN 37061) with generally good reputation. The ISP Safaricom maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Long-term blocking recommended.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 4/10 Low
Confidence Score 60% High Confidence

Confidence History

22. Nov. 2025 - 23. Juli 2026
62% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Hacking Exploited Host Honeypot x2 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
41.139.172.151
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
KE KE
ASN
AS37061
ISP
Safaricom

DNS-Informationen

Reverse DNS
41-139-172-151.safaricombusiness.co.ke
PTR-Eintrag
Ja
Verbindungstyp
Dynamisch

Statistiken

Gesamtzahl der Reports
1.040
Erstmals gemeldet
21 Nov. 2025
Zuletzt gemeldet
23 Juli 2026, 17:06

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS37061
Safaricom
KE KE

Bewertung von Netzwerkbedrohungen

1/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

39
Gesamtzahl der überwachten IP-Adressen
2,092
Gesamtzahl der Reports
53.6
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu Safaricom (AS 37061), das in unserem Überwachungssystem 39 IP-Adressen verwaltet. Von diesen wurden 2,092 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 1 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

92 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 92 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.496

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 1.040 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 75 im ASN 37061

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 7,3 +
Gesamtzahl der Reports 1.040 Netzwerk-Durchschnitt: 32 ++
Der Netzwerk-Safaricom hat eine Gesamtbedrohungsstufe von 1 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 737 in KE

Gefahrenstufe 10/10 Landesdurchschnitt: 6,4 ++
Gesamtzahl der Reports 1.040 Landesdurchschnitt: 6 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
9.1/10 Durchschnittliche Bedrohung
73% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert
197.248.89.127 8/10
Selbstvertrauen 97%
Reports 26
Standort KE KE
197.248.207.139 10/10
Selbstvertrauen 93%
Reports 57
Standort KE KE
197.248.152.251 8/10
Selbstvertrauen 85%
Reports 16
Standort KE KE
41.90.100.147 10/10
Selbstvertrauen 84%
Reports 73
Standort KE KE
197.248.104.31 8/10
Selbstvertrauen 82%
Reports 45
Standort KE KE
197.248.8.33 8/10
Selbstvertrauen 81%
Reports 84
Standort KE KE
197.248.104.19 8/10
Selbstvertrauen 81%
Reports 48
Standort KE KE
197.248.114.217 10/10
Selbstvertrauen 76%
Reports 30
Standort KE KE
197.248.144.117 10/10
Selbstvertrauen 75%
Reports 556
Standort KE KE
197.248.34.233 10/10
Selbstvertrauen 74%
Reports 21
Standort KE KE
197.248.159.242 10/10
Selbstvertrauen 73%
Reports 21
Standort KE KE
197.248.25.117 8/10
Selbstvertrauen 70%
Reports 9
Standort KE KE
197.248.238.153 10/10
Selbstvertrauen 65%
Reports 70
Standort KE KE
197.248.223.210 8/10
Selbstvertrauen 65%
Reports 4
Standort KE KE
41.139.135.161 10/10
Selbstvertrauen 64%
Reports 84
Standort KE KE
41.139.159.137 10/10
Selbstvertrauen 62%
Reports 5
Standort KE KE
197.248.169.83 8/10
Selbstvertrauen 62%
Reports 5
Standort KE KE
41.203.212.53 8/10
Selbstvertrauen 61%
Reports 19
Standort KE KE
41.139.139.5 10/10
Selbstvertrauen 57%
Reports 6
Standort KE KE
197.248.231.143 10/10
Selbstvertrauen 55%
Reports 7
Standort KE KE

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "41.139.172.151",
    "threat_level": 10,
    "confidence_score": 62,
    "total_reports": 1040,
    "country_code": "KE",
    "isp_name": "Safaricom",
    "asn": "37061",
    "first_reported": "2025-11-21 12:58:57",
    "last_reported": "2026-07-23 17:06:24",
    "exported_at": "2026-08-06T20:21:42+02:00",
    "source": "https://reportedip.com/ip/41.139.172.151/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.