IP-Adresse

80.94.95.83

IPv4 Öffentlich
RO RO
AS204428
SS-Net
765 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
10/10 Bedrohung
85% Selbstvertrauen
765 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 5% Most Dangerous
RO
RO Standort
SS-Net ASN 204428
765 Reports
Honeypot Datenquelle

Critical Threat

IP 80.94.95.83 is a critical-risk address that automated honeypot sensors flagged 457 times over approximately seven months, making it one of the most actively threatening Romanian IPs documented in recent threat-intelligence collections. With a threat level of 10 out of 10 and a confidence score of 94 percent, this address has been definitively associated with sustained hacking activity including intrusion attempts and exploitation probes against exposed services. The combination of extremely high report volume, consistent activity frequency rated at 8 out of 10, and detection across multiple independent honeypot sensors leaves no reasonable doubt about its malicious intent.

The detection data shows that all 457 reports originated from automated honeypot sensors, indicating that this address is systematically scanning or attacking widely deployed internet-facing systems. Activity was first logged in December 2025 and continued through June 2026, demonstrating persistent engagement over the observation period. The IP routes through AS204428, operated by SS-Net, and is geolocated to Romania. The reported threat category is Hacking, and the specific attack pattern observed includes anomalous TCP stream behavior where acknowledgment packets arrive in an unexpected sequence. This pattern is consistent with reconnaissance probes or techniques designed to test firewall and intrusion-detection reaction times.

Hacking activity at this volume and consistency represents a genuine risk to any exposed service. Intrusion attempts and exploitation probes can lead to unauthorized access, data exfiltration, or deployment of secondary payloads if a vulnerable entry point is found. The detected TCP anomaly pattern suggests the source may be actively fingerprinting network defenses or attempting to elicit unexpected responses from stateful inspection devices. Organizations with remote access services, web interfaces, or other internet-facing applications are the most directly exposed to this type of automated threat.

Site operators should block IP 80.94.95.83 at the network perimeter immediately and monitor logs for any related connection attempts. Implementing automated blocking tools such as fail2ban or equivalent intrusion-prevention solutions can detect repeated authentication failures or scanning behavior and apply temporary or permanent bans dynamically. Keeping all exposed systems fully patched and enforcing strong authentication requirements on remote-access services substantially reduces the likelihood of successful compromise. Deploying or updating network-based intrusion detection signatures to flag anomalous TCP acknowledgment patterns provides an additional layer of defense against this specific reconnaissance technique.

Bedrohlicher als „97“ % der überwachten IP-Adressen

Threat Categories

Hacking 30

Technische Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Empfohlene Abhilfemaßnahmen

Keep systems patched, implement intrusion detection, and follow security best practices.

Verhaltensanalyse

Aktivitätsmuster: Consistent Activity

Steady malicious activity over 4 weeks indicates persistent threat actor operations.

Erstmals beobachtet 8. Juli 2026
Letzte Aktivität 6. August 2026
Aktuell (7 Tage) 27 Vorfälle

High-Risk Network Association

This IP belongs to a network (ASN 204428) with elevated threat levels. The ISP SS-Net hosts multiple reported malicious addresses, suggesting systemic security issues or permissive policies.

Network-wide patterns may indicate this is part of a larger malicious infrastructure.

Sicherheitsempfehlungen

Long-term blocking recommended.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 8/10 High
Confidence Score 85% Verified

Confidence History

30. Juli 2026 - 6. Aug. 2026
85% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Neu Hacking Honeypot 75%
Neu Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
80.94.95.83
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
RO RO
ASN
AS204428
ISP
SS-Net

DNS-Informationen

Reverse DNS
Keine
PTR-Eintrag
Nein
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
765
Erstmals gemeldet
3 Dez. 2025
Zuletzt gemeldet
6 Aug. 2026, 15:12

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS204428
SS-Net
RO RO

Bewertung von Netzwerkbedrohungen

8/10
Dieses Netzwerk weist ein hohes Bedrohungsniveau auf, wobei über mehrere IP-Adressen hinweg erhebliche böswillige Aktivitäten gemeldet wurden.

Netzwerkstatistiken

43
Gesamtzahl der überwachten IP-Adressen
36,130
Gesamtzahl der Reports
840.2
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu SS-Net (AS 204428), das in unserem Überwachungssystem 43 IP-Adressen verwaltet. Von diesen wurden 36,130 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 8 /10 geführt hat.

Netzwerkwarnung: In diesem Netzwerk besteht eine erhöhte Sicherheitsbedrohung. Seien Sie vorsichtig, wenn Sie mit IP-Adressen aus diesem ASN interagieren.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

97 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 97 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.072

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 765 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 46 im ASN 204428

Gefahrenstufe 10/10 Netzwerk-Durchschnitt: 8,0 +
Gesamtzahl der Reports 765 Netzwerk-Durchschnitt: 807 =
Der Netzwerk-SS-Net hat eine Gesamtbedrohungsstufe von 8 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 970 in RO

Gefahrenstufe 10/10 Landesdurchschnitt: 6,6 ++
Gesamtzahl der Reports 765 Landesdurchschnitt: 178 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.633 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.619 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.774 22.5%
  2. 02
    IN
    India IN
    49.098 16.8%
  3. 03
    CN
    China CN
    35.622 12.2%
  4. 04
    BR
    Brazil BR
    15.554 5.3%
  5. 05
    DE
    Germany DE
    10.499 3.6%
  6. 06
    PK
    Pakistan PK
    8.474 2.9%
  7. 07
    ID
    Indonesia ID
    8.403 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.393 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
9.5/10 Durchschnittliche Bedrohung
80% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

IP-Adressen aus demselben Subnetzbereich, vermutlich aus demselben Netzwerksegment.

20 Verwandte IPs
9.5/10 Durchschnittliche Bedrohung
80% Durchschnittliche Konfidenz
20 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "80.94.95.83",
    "threat_level": 10,
    "confidence_score": 85,
    "total_reports": 765,
    "country_code": "RO",
    "isp_name": "SS-Net",
    "asn": "204428",
    "first_reported": "2025-12-03 12:59:28",
    "last_reported": "2026-08-06 15:12:17",
    "exported_at": "2026-08-06T15:53:40+02:00",
    "source": "https://reportedip.com/ip/80.94.95.83/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.