IP-Adresse

95.110.231.151

IPv4 Öffentlich
IT IT
AS31034
Aruba S.p.A.
397 Reports
Diese IP-Adresse steht auf der Blacklist Bedrohung mit hoher Einstufung – Blockierung empfohlen
8/10 Bedrohung
82% Selbstvertrauen
397 Reports

Analyse von Threat Intelligence

KI-gestützte Sicherheitsbewertung auf der Grundlage aggregierter Bedrohungsdaten

Above Average Risk
IT
IT Standort
Aruba S.p.A. ASN 31034
397 Reports
Honeypot Datenquelle

High Risk

IP 95.110.231.151 is a high-risk Italian address associated with 397 reported incidents, predominantly SSH brute-force activity detected by automated honeypot sensors, presenting a credible threat to exposed remote-access services. The address, operated by Aruba S.p.A. under ASN AS31034, carries an 8/10 threat level with an 82% confidence rating, indicating substantial corroboration across multiple detection sources during its active window in December 2025.

Community reports and automated honeypot sensors logged the bulk of this activity, with fail2ban triggering repeatedly on sshd connections, confirming systematic password-guessing behaviour rather than opportunistic scanning. Despite a high total report volume of 397 incidents, the activity frequency score of 0/10 suggests the attacks were concentrated in a specific period rather than sustained over time, consistent with coordinated scanning campaigns that target broad IP ranges in short bursts. The Italian network ownership through Aruba S.p.A., a major European hosting provider, places this source within infrastructure commonly abused for anonymised attack traffic due to its commercial hosting model.

SSH brute-force attacks represent one of the most persistent threats to internet-exposed servers, exploiting weak or default credentials to gain unauthorised shell access. Once inside, attackers typically deploy backdoors, cryptocurrency miners or pivot further into internal networks, making initial access a critical breach point. The repeated detection by fail2ban confirms that the address is actively scanning for accessible SSH daemons, with each failed authentication attempt consuming server resources and generating log noise that can obscure genuine login attempts.

Operators running accessible SSH services should enforce key-based authentication exclusively, disable password-based login entirely, and move the service to a non-standard port to reduce exposure surface. Implementing fail2ban with aggressive ban thresholds tailored to sshd will automatically block repeated source addresses like 95.110.231.151. Additionally, restricting SSH access to known IP ranges via firewall rules or VPN jump hosts and monitoring authentication logs for patterns matching this address will further harden defences against similar scanning activity.

Bedrohlicher als „84“ % der überwachten IP-Adressen

Threat Categories

SSH 30

Technische Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Empfohlene Abhilfemaßnahmen

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Moderate Network Risk

The network hosting this IP (ASN 31034, operated by Aruba S.p.A.) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Sicherheitsempfehlungen

Continue monitoring for emerging patterns.

Diese Analyse wird automatisch aus aggregierten, anonymisierten Threat Intelligence-Daten generiert. Es werden keine personenbezogenen Daten angezeigt oder gespeichert. Die Genauigkeit der Auswertung hängt vom Umfang und der Vielfalt der verfügbaren Daten ab.

Reputation Summary

Gefahrenstufe 8/10 High
Critical
Häufigkeit der Aktivitäten 0/10 Inactive
Confidence Score 62% High Confidence

Confidence History

15. Dez. 2025
82% Aktuell
Stable Trend

Der Confidence Score gibt die Zuverlässigkeit der Bedrohungsbewertung auf der Grundlage der Anzahl und der Qualität der Reports an.

Sicherheitsreports (30)

Datum Kategorien Quelle Selbstvertrauen
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technische Details

Grundlegende Informationen

IP-Adresse
95.110.231.151
IP-Version
IPv4
Netzwerktyp
Öffentlich
Tor-Netzwerk
Nein
Netzwerkklasse
Class A

Geolokalisierung

Land
IT IT
ASN
AS31034
ISP
Aruba S.p.A.

DNS-Informationen

Reverse DNS
host151-231-110-95.serverdedicati.aruba.it
PTR-Eintrag
Ja
Verbindungstyp
Dynamisch

Statistiken

Gesamtzahl der Reports
397
Erstmals gemeldet
13 Dez. 2025
Zuletzt gemeldet
15 Dez. 2025, 11:35

Netzwerk-Reputation

Analyse des gesamten Netzwerks (ASN), zu dem diese IP-Adresse gehört, um Informationen zum Hosting-Anbieter und zu netzwerkweiten Bedrohungsmustern zu liefern.

Netzwerkidentität

AS31034
Aruba S.p.A.
IT IT

Bewertung von Netzwerkbedrohungen

4/10
Dieses Netzwerk weist geringe Bedrohungsindikatoren und nur minimale verdächtige Aktivitäten auf.

Netzwerkstatistiken

22
Gesamtzahl der überwachten IP-Adressen
662
Gesamtzahl der Reports
30.1
Reports pro IP-Adresse

Netzwerkkontext

Diese IP-Adresse gehört zu Aruba S.p.A. (AS 31034), das in unserem Überwachungssystem 22 IP-Adressen verwaltet. Von diesen wurden 662 wegen verdächtiger Aktivitäten gemeldet, was zu einer netzwerkweiten Gefahrenstufe von 4 /10 geführt hat.

Netzwerkhinweis: Dieses Netzwerk weist einige verdächtige Aktivitätsmuster auf. Bitte überwachen Sie die Interaktionen mit IP-Adressen aus diesem ASN.

Vergleichende Analyse

Wie sich diese IP-Adresse im Vergleich zu anderen in unserer Threat Intelligence-Datenbank darstellt

84 %

Globales Bedrohungsranking

Diese IP-Adresse stellt von allen IP-Adressen in unserer Datenbank die größte Bedrohung dar: 84 %.

Prozentil für hohes Risiko

Globaler Vergleich

Im Vergleich zu den weltweit gemeldeten IP-Adressen auf 312.445

Gefahrenstufe 8/10 avg: 6,0 +
Gesamtzahl der Reports 397 avg: 18 ++

Netzwerkvergleich

Im Vergleich zu den IP-Adressen unter 30 im ASN 31034

Gefahrenstufe 8/10 Netzwerk-Durchschnitt: 6,1 +
Gesamtzahl der Reports 397 Netzwerk-Durchschnitt: 22 ++
Der Netzwerk-Aruba S.p.A. hat eine Gesamtbedrohungsstufe von 4 /10

Geografischer Vergleich

Im Vergleich zu den IP-Adressen unter 1.589 in IT

Gefahrenstufe 8/10 Landesdurchschnitt: 5,2 ++
Gesamtzahl der Reports 397 Landesdurchschnitt: 8 ++
Kennzahlen:
++ Deutlich höher + Höher = Ähnlich - Nach unten -- Deutlich niedriger

Geografische Verteilung der Bedrohungen

292.711 Weltweit erfasste Sicherheitsvorfälle • In den letzten 24 Stunden: 17.660 Protokolle

FEED

Die größten Bedrohungsquellen

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 weitere Länder

GEFAHRENSTUFE
NIEDRIG MED HOCH

Geografische Daten werden aggregiert und anonymisiert. Es werden keine personenbezogenen Daten angezeigt.

Karte: simplemaps.com (MIT License)

Verwandte IPs

Weitere IP-Adressen, die aufgrund von Netzwerk- oder Verhaltensähnlichkeiten mit dieser Adresse in Verbindung stehen

IP-Adressen desselben Netzbetreibers aus demselben autonomen System (AS).

20 Verwandte IPs
5.6/10 Durchschnittliche Bedrohung
40% Durchschnittliche Konfidenz
12 Hohe Bedrohung
Risikoreiches Netzwerk: Die Mehrheit der zugehörigen IP-Adressen ist markiert

IP-Adressen aus demselben Subnetzbereich, vermutlich aus demselben Netzwerksegment.

1 Verwandte IPs
5/10 Durchschnittliche Bedrohung
5% Durchschnittliche Konfidenz

Export- und Firewall Rules

Laden Sie Bedrohungsdaten herunter oder erstellen Sie Firewall Rules, um diese IP-Adresse zu blockieren

JSON-Bericht

Strukturiertes Datenformat für die Integration mit Sicherheitstools und SIEM-Systemen.

{
    "ip_address": "95.110.231.151",
    "threat_level": 8,
    "confidence_score": 82,
    "total_reports": 397,
    "country_code": "IT",
    "isp_name": "Aruba S.p.A.",
    "asn": "31034",
    "first_reported": "2025-12-13 23:35:45",
    "last_reported": "2025-12-15 11:35:38",
    "exported_at": "2026-08-06T19:41:47+02:00",
    "source": "https://reportedip.com/ip/95.110.231.151/"
}

GDPR Compliant: Die Exporte enthalten ausschließlich IP-bezogene Bedrohungsdaten. Es sind weder personenbezogene Daten noch Angaben zum Melder enthalten.