IP-Adresse

50.6.226.221

IPv4 Öffentlich
US US
AS31898
ORACLE-BMC-31898
223 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
10/10 Bedrohung
100% Selbstvertrauen
223 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 5% Most Dangerous
US
US Standort
ORACLE-BMC-31898 ASN 31898
223 Reports
Gemischt Datenquelle

Critical Alert

IP 50.6.226.221, registered to Oracle BMC (AS31898) in the United States, is a critical-risk address that has generated 223 abuse reports across automated honeypot sensors and community sources since February 2026, making it one of the most actively hostile IPs observed in recent weeks. With a perfect confidence score and the highest possible threat rating, the evidence base is unambiguous: this single address has been linked simultaneously to WordPress login brute-force attacks, WordPress XML-RPC abuse, unauthorized cron execution, distributed denial-of-service activity, and site-level resource exhaustion.

The report distribution reveals a broad, multi-vector assault on WordPress infrastructure. WordPress login brute-force attempts lead the categories at 20 reports, followed by generic brute-force activity at 14, WordPress cron abuse at 11, DDoS participation at 11, and resource exhaustion at 9. Seven automated honeypot sensors and 13 separate community sources filed these 223 reports within a compressed February–March 2026 window, reflecting both high activity volume and wide geographic detection coverage. Network log excerpts corroborate the pattern, showing simultaneous unauthorized cron execution, brute-force login probes against the root URI, and XML-RPC vulnerability scanning, all driving server memory consumption above 86–90 MB per request and query counts reaching 94–106 per event.

WordPress brute-force attacks systematically cycle credential combinations against wp-login.php, exploiting weak or default admin passwords to gain backend access. The companion XML-RPC abuse exploits the pingback API as both a credential-guessing vector and an amplification reflector for DDoS traffic, while unauthorized cron execution forces the server to repeatedly run scheduled tasks, degrading performance and consuming database resources. Together these techniques form a compound threat: an attacker gaining WordPress admin access can deploy web shells, inject malware, pivot to hosted databases, or enlist the server into a botnet. The resource exhaustion logs confirm the target servers are already under measurable strain.

Site operators running WordPress should block this IP immediately at the firewall or network edge, and implement rate limiting on authentication endpoints to throttle repeated login attempts. Deploying tools such as fail2ban to detect and auto-block WordPress-specific attack patterns provides an automated first line of defense. Disabling the XML-RPC interface entirely (via .htaccess or a security plugin) eliminates both the brute-force and DDoS amplification vector. Enforcing strong password policies, limiting admin access by IP whitelisting where feasible, and monitoring server resource consumption for the spike signatures documented here will further reduce exposure.

Bedrohlicher als „100“ % der überwachten IP-Adressen

Threat Categories

WP Login Brute Force 28
Brute-Force 20
DDoS Attack 17
WP Cron Abuse 16
WP Resource Exhaustion 11
Hacking 10

Reputable Network

This IP is hosted on a network (ASN 31898) with generally good reputation. The ISP ORACLE-BMC-31898 maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Continue monitoring for emerging patterns.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 8/10 High
Confidence Score 44% Medium Confidence

Confidence History

1. März 2026 - 2. März 2026
100% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
WP Login Brute Force Brute-Force WP Cron Abuse +1 Community x4 75%
WP Cron Abuse DDoS Attack WP Login Brute Force Community x2 75%
WP Login Brute Force Brute-Force WP Resource Exhaustion +2 Community x3 75%
WP XML-RPC Brute Force Hacking WP Resource Exhaustion +4 Community x6 75%
WP XML-RPC Brute Force Hacking WP Cron Abuse +4 Community x5 75%
WP Login Brute Force Honeypot 75%
WP XML-RPC Brute Force Hacking WP Login Brute Force +1 Community x2 75%
WP Login Brute Force Brute-Force WP XML-RPC Brute Force +4 Community x5 75%
WP Login Brute Force Honeypot 75%
WP Cron Abuse DDoS Attack WP Resource Exhaustion +2 Community x5 75%
WP Login Brute Force Honeypot 75%
WP Login Brute Force Brute-Force WP XML-RPC Brute Force +4 Community x5 75%
WP XML-RPC Brute Force Hacking WP Login Brute Force +1 Community x2 75%
WP Login Brute Force Honeypot 75%
WP Login Brute Force Brute-Force WP Cron Abuse +2 Community x4 75%
WP Cron Abuse DDoS Attack WP Resource Exhaustion +2 Community x4 75%
WP Login Brute Force Honeypot 75%
WP Login Brute Force Brute-Force WP Resource Exhaustion +2 Community x5 75%
WP Login Brute Force Hacking Brute-Force Honeypot x2 75%
WP Login Brute Force Brute-Force Honeypot x2 75%
WP Cron Abuse DDoS Attack WP Resource Exhaustion +2 Community x4 75%
WP Cron Abuse DDoS Attack WP Resource Exhaustion +2 Community x5 75%
WP Login Brute Force Hacking Brute-Force Honeypot x2 75%
WP Cron Abuse DDoS Attack Community 75%
WP Cron Abuse DDoS Attack WP Login Brute Force +1 Community x5 75%
WP Login Brute Force Honeypot 75%
WP Cron Abuse DDoS Attack WP Login Brute Force +1 Community x2 75%
Hacking DDoS Attack Community 75%
WP Login Brute Force Honeypot 75%
WP Login Brute Force Brute-Force WP XML-RPC Brute Force +1 Community x3 75%

Technische Details

Grundlegende Informationen

IP-Adresse
50.6.226.221
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
US US
ASN
AS31898
ISP
ORACLE-BMC-31898

DNS-Informationen

Reverse DNS
server.rippa.com
PTR-Eintrag
Ja
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
223
Erstmals gemeldet
20 Feb. 2026
Zuletzt gemeldet
2 März 2026, 13:52

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS31898
Oracle Corporation
SG SG

Bewertung von Netzwerkbedrohungen

2/10
Dieses Netzwerk scheint relativ sicher zu sein und weist nur sehr wenige Anzeichen für Sicherheitsrisiken auf.

Netzwerkstatistiken

445
Gesamtzahl der überwachten IP-Adressen
8,338
Gesamtzahl der Reports
18.7
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu Oracle Corporation (AS 31898), das in unserem Überwachungssystem 445 IP-Adressen verwaltet. Von diesen wurden 8,338 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 2 /10 geführt hat.

Netzwerkstatus: Dieses Netzwerk scheint gut gewartet zu sein und weist nur geringe Sicherheitsrisiken auf.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

100 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 100 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.082

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 223 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 996 im ASN 31898

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 6,6 ++
Gesamtzahl der Reports 223 Netzwerk-Durchschnitt: 14 ++
Der Netzwerk-ORACLE-BMC-31898 hat eine Gesamtbedrohungsstufe von 2 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 65.787 in US

Gefahrenstufe 10/10 Landesdurchschnitt: 6,5 ++
Gesamtzahl der Reports 223 Landesdurchschnitt: 31 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.633 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.619 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US DIESE IP-ADRESSE
    65.774 22.5%
  2. 02
    IN
    India IN
    49.098 16.8%
  3. 03
    CN
    China CN
    35.622 12.2%
  4. 04
    BR
    Brazil BR
    15.554 5.3%
  5. 05
    DE
    Germany DE
    10.499 3.6%
  6. 06
    PK
    Pakistan PK
    8.474 2.9%
  7. 07
    ID
    Indonesia ID
    8.403 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.393 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
8.8/10 Durchschnittliche Bedrohung
100% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert
74.91.224.220 8/10
Selbstvertrauen 100%
Reports 490
Standort SG SG
50.6.7.129 8/10
Selbstvertrauen 100%
Reports 447
Standort US US
50.6.229.148 8/10
Selbstvertrauen 100%
Reports 346
Standort US US
158.179.210.22 10/10
Selbstvertrauen 100%
Reports 87
Standort ES ES
50.6.224.46 8/10
Selbstvertrauen 100%
Reports 85
Standort US US
129.121.76.191 8/10
Selbstvertrauen 100%
Reports 82
Standort US US
129.121.41.228 8/10
Selbstvertrauen 100%
Reports 79
Standort BR BR
50.87.144.169 10/10
Selbstvertrauen 100%
Reports 66
Standort US US
66.116.235.214 8/10
Selbstvertrauen 100%
Reports 63
Standort AE AE
50.6.231.19 8/10
Selbstvertrauen 100%
Reports 57
Standort US US
150.136.244.33 8/10
Selbstvertrauen 100%
Reports 48
Standort US US
162.144.12.37 10/10
Selbstvertrauen 100%
Reports 47
Standort US US
129.121.77.87 8/10
Selbstvertrauen 100%
Reports 44
Standort US US
67.20.116.98 8/10
Selbstvertrauen 100%
Reports 42
Standort US US
50.87.144.11 10/10
Selbstvertrauen 100%
Reports 39
Standort US US
150.136.214.177 10/10
Selbstvertrauen 100%
Reports 38
Standort US US
50.6.228.32 10/10
Selbstvertrauen 100%
Reports 38
Standort US US
161.118.210.105 8/10
Selbstvertrauen 100%
Reports 32
Standort SG SG
150.136.129.10 10/10
Selbstvertrauen 100%
Reports 32
Standort US US
50.87.144.147 10/10
Selbstvertrauen 100%
Reports 31
Standort US US

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
8.3/10 Durchschnittliche Bedrohung
100% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "50.6.226.221",
    "threat_level": 10,
    "confidence_score": 100,
    "total_reports": 223,
    "country_code": "US",
    "isp_name": "ORACLE-BMC-31898",
    "asn": "31898",
    "first_reported": "2026-02-20 15:16:43",
    "last_reported": "2026-03-02 13:52:28",
    "exported_at": "2026-08-06T16:02:41+02:00",
    "source": "https://reportedip.com/ip/50.6.226.221/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.