Dirección IP

196.191.254.26

IPv4 Público
ET ET
AS24757
Ethiopian Telecommunication Corporation
408 Reports
Esta dirección IP figura en la Blacklist Amenaza de alta fiabilidad: se recomienda bloquearla
10/10 Amenaza
94% Confianza
408 Reports

Análisis de Threat Intelligence

Evaluación de seguridad generada por IA basada en datos agregados sobre amenazas

Top 5% Most Dangerous
ET
ET Ubicación
Ethiopian Telecommunicati... ASN 24757
408 Reports
Honeypot Fuente de datos

Severe Risk

IP 196.191.254.26 is a critical-risk address associated with an exploited host that has generated 408 abuse reports, indicating sustained malicious activity originating from a compromised system within Ethiopian Telecommunication Corporation's network (ASN AS24757). The IP has been flagged with a maximum threat score of 10/10 and an activity frequency rating of 8/10, reflecting continuous engagement in malware and exploit-related operations over the December 2025 reporting window. Detection across 20 independent automated honeypot sensors confirms a 94% confidence level that this address is actively participating in hostile operations without the knowledge of its legitimate operator.

The 408 total reports and high activity frequency establish this as one of the most actively reported addresses in the observed timeframe. All 20 report sources are automated honeypot sensors, which detected exploit-oriented activity consistent with a compromised host being weaponized for external attacks. Ethiopian Telecommunication Corporation operates the underlying network infrastructure, but the address itself shows clear signs of having fallen under unauthorized control. The geographic attribution to Ethiopia (ET) and the concentration of identical honeypot detections point to automated scanning and exploitation activity rather than isolated manual attempts.

An exploited host presents a concrete and serious threat because the machine is being weaponized remotely, typically through malware or remote access tooling, while its owner remains unaware. Attackers leverage such compromised infrastructure to conduct scanning, exploit delivery, credential abuse or further propagation of malicious payloads against other targets globally. For network defenders, an exploited host in a foreign network means attacks may carry the weight of a seemingly legitimate residential or corporate IP, making detection and attribution harder for victims' defensive systems. The real-world risk extends beyond this single address: it represents a node in a potential botnet or attack chain that could affect any exposed service on the internet.

Site operators should immediately block IP 196.191.254.26 at the network perimeter and monitor logs for any related attempt patterns. Deploying or strengthening rate-limiting and brute-force protection mechanisms—such as fail2ban or equivalent tools—reduces the impact of similar scanning activity from this source. Enforcing strong authentication on exposed services, applying least-privilege access controls and maintaining up-to-date patching across all internet-facing systems limits the effectiveness of any exploitation attempts. Organizations experiencing repeated contact from this address should consider filing an abuse report with Ethiopian Telecommunication Corporation to facilitate remediation of the compromised host at its source.

Más amenazante que 98 % de direcciones IP supervisadas

Threat Categories

Exploited Host 30

Detalles técnicos

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Medidas de mitigación recomendadas

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Moderate Network Risk

The network hosting this IP (ASN 24757, operated by Ethiopian Telecommunication Corporation) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Recomendaciones de seguridad

Continue monitoring for emerging patterns.

Este análisis se genera automáticamente a partir de datos agregados y anonimizados de Threat Intelligence. No se muestra ni se almacena ninguna información personal. La precisión de la evaluación depende del volumen y la diversidad de los datos disponibles.

Reputation Summary

Nivel de amenaza 10/10 Critical
Critical
Frecuencia de la actividad 8/10 High
Confidence Score 59% High Confidence

Confidence History

28. Dic 2025
94% Actual
Stable Tendencia

El Confidence Score indica la fiabilidad de la evaluación de la amenaza en función del número y la calidad de los informes.

Informes de seguridad (30)

Fecha Categorías Fuente Confianza
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Detalles técnicos

Información básica

Dirección IP
196.191.254.26
Versión de IP
IPv4
Tipo de red
Público
Red Tor
No
Clase de red
Class C

Geolocalización

País
ET ET
ASN
AS24757
ISP
Ethiopian Telecommunication Corporation

Información sobre el DNS

Reverse DNS
Ninguno
Récord en el PTR
No
Tipo de conexión
Estático

Estadísticas

Total Reports
408
Publicado por primera vez en Reports
27 Dic 2025
Última actualización de Reports
28 Dic 2025, 05:11

Reputación en la red

Análisis de toda la red (ASN) a la que pertenece esta dirección IP, lo que proporciona información sobre el proveedor de alojamiento y los patrones de amenazas a nivel de red.

Identidad de red

AS24757
Ethiopian Telecommunication Corporation
ET ET

Evaluación de amenazas a la red

5/10
Esta red presenta bajos indicadores de amenaza y una actividad sospechosa mínima.

Estadísticas de red

178
Total de direcciones IP supervisadas
2,256
Total Reports
12.7
Reports por IP

Contexto de red

Esta dirección IP pertenece a Ethiopian Telecommunication Corporation (AS 24757), que gestiona 178 direcciones IP en nuestro sistema de monitorización. De ellas, 2,256 han sido señaladas por actividades sospechosas, lo que ha dado lugar a un nivel de amenaza para toda la red de 5 /10.

Aviso de la red: Esta red muestra algunos patrones de actividad sospechosos. Supervisa las interacciones con las direcciones IP de este ASN.

Análisis comparativo

Cómo se compara esta dirección IP con otras de nuestra base de datos de Threat Intelligence

98 %

Clasificación mundial de amenazas

Esta dirección IP es más peligrosa que 98 % de todas las direcciones IP de nuestra base de datos.

El 10 % más peligroso

Comparación mundial

Comparado con las direcciones IP registradas en todo el mundo en 312.365

Nivel de amenaza 10/10 promedio: 6,0 ++
Total Reports 408 promedio: 18 ++

Comparación de redes

Comparado con las direcciones IP 297 del ASN 24757

Nivel de amenaza 10/10 Promedio de la red: 6,2 ++
Total Reports 408 Promedio de la red: 9 ++
La red Ethiopian Telecommunication Corporation tiene un nivel de amenaza global de 5 /10

Comparación geográfica

Comparado con las direcciones IP de 328 en ET

Nivel de amenaza 10/10 Media nacional: 6,2 ++
Total Reports 408 Media nacional: 8 ++
Indicadores:
++ Mucho más alto + Más alto = Similar - Inferior -- Mucho más bajo

Distribución geográfica de las amenazas

292.711 incidentes de amenazas registrados a nivel mundial • Últimas 24 horas: 17.660 Registros

FEED

Principales fuentes de amenazas

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 más países

NIVEL DE AMENAZA
BAJO MED ALTO

Los datos geográficos se agrupan y se anonimizan. No se muestra ninguna información personal.

Mapa: simplemaps.com (MIT License)

IP relacionadas

Otras direcciones IP asociadas a esta dirección por similitud de red o de comportamiento

Direcciones IP del mismo proveedor de red del sistema autónomo (AS).

20 IP relacionadas
9.4/10 Amenaza media
87% Confianza media
20 Alto riesgo
Red de alto riesgo: la mayoría de las direcciones IP relacionadas están marcadas

Direcciones IP del mismo rango de subred, probablemente del mismo segmento de red.

1 IP relacionadas
0/10 Amenaza media
30% Confianza media

Reglas de exportación y Firewall Rules

Descarga datos sobre amenazas o genera Firewall Rules para bloquear esta IP

Informe JSON

Formato de datos estructurados para la integración con herramientas de seguridad y sistemas SIEM.

{
    "ip_address": "196.191.254.26",
    "threat_level": 10,
    "confidence_score": 94,
    "total_reports": 408,
    "country_code": "ET",
    "isp_name": "Ethiopian Telecommunication Corporation",
    "asn": "24757",
    "first_reported": "2025-12-27 14:29:55",
    "last_reported": "2025-12-28 05:11:19",
    "exported_at": "2026-08-06T18:34:36+02:00",
    "source": "https://reportedip.com/ip/196.191.254.26/"
}

GDPR Compliant: Las exportaciones contienen únicamente datos sobre amenazas relacionados con direcciones IP. No se incluye ninguna información personal ni datos del informante.