IP-Adresse

91.92.241.148

IPv4 Öffentlich
BG BG
Neterra Ltd
7.812 Reports
Diese IP-Adresse steht unter Beobachtung Verdächtige Aktivität festgestellt – bitte genau beobachten
10/10 Bedrohung
59% Selbstvertrauen
7.812 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Top 10% High Threat
BG
BG Standort
Neterra Ltd ISP
7.812 Reports
Honeypot Datenquelle

Critical Threat

IP 91.92.241.148, registered in Bulgaria and operated by Neterra Ltd, presents a severe threat profile with a maximum threat level of 10/10 based on 7,812 total abuse reports, primarily involving SSH brute-force intrusion attempts detected across 20 automated honeypot sensors. While activity frequency has dropped to zero in recent intervals, the sheer volume of historical reports establishes this address as a confirmed, persistent attack platform that has systematically targeted SSH services over a six-month period from September 2025 through March 2026.

The detection data reveals consistent engagement in brute-force authentication attacks against exposed SSH daemons, with Suricata signatures confirming active session establishment attempts on expected ports. The 7,812 reports span three distinct but related threat categories: general hacking activity at 19 reports, SSH-specific attacks at 18 reports, and two instances flagged as exploited host behaviour, suggesting this infrastructure may itself have been leveraged to compromise additional systems. The 60% confidence score reflects some uncertainty in attribution, yet the pattern of automated honeypot detections consistently points to credential-guessing campaigns rather than isolated scanning.

SSH brute-force activity represents one of the most prevalent and effective attack vectors targeting internet-exposed Linux servers and network devices. Attackers leverage automated tooling to cycle through credential combinations, exploiting weak or default passwords to gain unauthenticated access. Successful compromise grants attackers root-level control, enabling data exfiltration, malware deployment, lateral movement within networks, or recruitment into botnets. Even failed attempts consume server resources, create auth logs, and indicate an active threat actor probing defences.

Administrators running publicly accessible SSH services should immediately implement defensive controls: enforce key-based authentication exclusively, relocate the service to a non-standard port, apply fail2ban or equivalent tools to dynamically block repeated authentication failures, and disable direct root login. Given the volume of reports associated with this IP, blocking 91.92.241.148 at the network perimeter is strongly recommended, and organizations observing connections from this address should treat them as confirmed hostile probes warranting immediate investigation and blocking.

Bedrohlicher als „91“ % der überwachten IP-Adressen

Threat Categories

Hacking 29
SSH 28
Exploited Host 2

Technische Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Empfohlene Abhilfemaßnahmen

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 0) with generally good reputation. The ISP Neterra Ltd maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Sicherheitsempfehlungen

Continue monitoring for emerging patterns.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 10/10 Critical
Critical
Häufigkeit der Aktivitäten 0/10 Inactive
Confidence Score 59% High Confidence

Confidence History

3. März 2026 - 4. März 2026
59% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Exploited Host Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
Exploited Host Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
SSH Hacking Honeypot x2 75%

Technische Details

Grundlegende Informationen

IP-Adresse
91.92.241.148
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
BG BG
ASN
Unbekannt
ISP
Neterra Ltd

DNS-Informationen

Reverse DNS
Keine
PTR-Eintrag
Nein
Verbindungstyp
Statisch

Statistiken

Gesamtzahl der Reports
7.812
Erstmals gemeldet
19 Sep. 2025
Zuletzt gemeldet
4 März 2026, 04:28

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

91 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 91 %.

Die gefährlichsten 10 %

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.568

Gefahrenstufe 10/10 avg: 6,0 ++
Gesamtzahl der Reports 7.812 avg: 18 ++

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 886 in BG

Gefahrenstufe 10/10 Landesdurchschnitt: 7,0 +
Gesamtzahl der Reports 7.812 Landesdurchschnitt: 115 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen aus demselben Subnetzbereich, vermutlich aus demselben Netzwerksegment.

20 Verwandte IPs
8.3/10 Durchschnittliche Bedrohung
60% Durchschnittliche Konfidenz
18 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

IP-Adressen aus demselben Land mit ähnlichen Bedrohungsprofilen.

15 Verwandte IPs
8.5/10 Durchschnittliche Bedrohung
100% Durchschnittliche Konfidenz
15 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "91.92.241.148",
    "threat_level": 10,
    "confidence_score": 59,
    "total_reports": 7812,
    "country_code": "BG",
    "isp_name": "Neterra Ltd",
    "asn": "0",
    "first_reported": "2025-09-19 06:17:44",
    "last_reported": "2026-03-04 04:28:43",
    "exported_at": "2026-08-06T21:35:11+02:00",
    "source": "https://reportedip.com/ip/91.92.241.148/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.