Dirección IP

58.9.10.203

IPv4 Público
TH TH
AS17552
True Online
497 Reports
Esta dirección IP está bajo vigilancia Se ha detectado una actividad sospechosa: vigílala de cerca
10/10 Amenaza
64% Confianza
497 Reports

Análisis de Threat Intelligence

Evaluación de seguridad generada por IA basada en datos agregados sobre amenazas

Top 10% High Threat
TH
TH Ubicación
True Online ASN 17552
497 Reports
Honeypot Fuente de datos

Critical Alert

IP 58.9.10.203 is a high-risk address originating from Thailand (AS17552, True Online) that has been linked to 497 reported incidents of hacking activity, with all recent detections originating from automated honeypot sensors between September and November 2025. Despite a current activity frequency rated at zero, the sheer volume of historical abuse reports combined with a maximum threat score of 10/10 establishes this IP as a persistent, credible danger to any exposed network services.

The 497 total abuse reports represent a substantial detection footprint, with 20 of the most recent reports specifically categorizing the activity as general hacking attempts including intrusion and unauthorized access attempts. All recent detections were captured by automated honeypot sensors, indicating that this address has been systematically probing for vulnerabilities across the threat intelligence community's sensor network. The IP's assignment to True Online's AS17552 infrastructure in Thailand places it within a major regional ISP, suggesting the source may be a compromised residential connection or a dedicated attack host operating within that network. The gap between the high report volume and the current zero activity frequency may indicate a dormant campaign or a shift in attacker infrastructure, though historical precedent suggests reactivation is possible.

Hacking activity encompasses a broad range of intrusion methodologies, including exploitation attempts against known vulnerabilities, brute-force authentication attacks, and reconnaissance probes designed to map exposed services. For an organization with SSH, RDP, web applications, or database services directly accessible from the internet, an IP with this many prior hacking reports represents a concrete risk of unauthorized access, data exfiltration, or establishment of a persistent foothold within the target environment. The 64% confidence score reflects that while the threat is well-documented, attribution beyond the IP address remains partially uncertain, which is typical for addresses that may be anonymized through compromised hosts or botnet participation.

Site operators should immediately block IP 58.9.10.203 at the firewall or network edge device to prevent any inbound connections from this source. Implementing automated blocking tools such as fail2ban or similar host-based intrusion prevention systems can dynamically ban IPs after repeated failed authentication attempts. All exposed services should enforce strong, unique credentials and disable root or administrative access where possible. Continuous monitoring of inbound connection logs for this address and similar scanning patterns from the same network range will help detect any reactivation of hostile activity.

Más amenazante que 93 % de direcciones IP supervisadas

Threat Categories

Hacking 30

Detalles técnicos

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Medidas de mitigación recomendadas

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 17552) with generally good reputation. The ISP True Online maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Recomendaciones de seguridad

Continue monitoring for emerging patterns.

Este análisis se genera automáticamente a partir de datos agregados y anonimizados de Threat Intelligence. No se muestra ni se almacena ninguna información personal. La precisión de la evaluación depende del volumen y la diversidad de los datos disponibles.

Reputation Summary

Nivel de amenaza 10/10 Critical
Critical
Frecuencia de la actividad 0/10 Inactive
Confidence Score 59% High Confidence

Confidence History

13. Oct 2025 - 8. Nov 2025
64% Actual
Stable Tendencia

El Confidence Score indica la fiabilidad de la evaluación de la amenaza en función del número y la calidad de los informes.

Informes de seguridad (30)

Fecha Categorías Fuente Confianza
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Detalles técnicos

Información básica

Dirección IP
58.9.10.203
Versión de IP
IPv4
Tipo de red
Público
Red Tor
No
Clase de red
Class A

Geolocalización

País
TH TH
ASN
AS17552
ISP
True Online

Información sobre el DNS

Reverse DNS
ppp-58-9-10-203.revip2.asianet.co.th
Récord en el PTR
Tipo de conexión
Dinámico

Estadísticas

Total Reports
497
Publicado por primera vez en Reports
28 Sep 2025
Última actualización de Reports
8 Nov 2025, 04:57

Reputación en la red

Análisis de toda la red (ASN) a la que pertenece esta dirección IP, lo que proporciona información sobre el proveedor de alojamiento y los patrones de amenazas a nivel de red.

Identidad de red

AS17552
True Online
TH TH

Evaluación de amenazas a la red

3/10
Esta red parece estar relativamente libre de amenazas, con unos indicadores de riesgo muy bajos.

Estadísticas de red

12
Total de direcciones IP supervisadas
519
Total Reports
43.3
Reports por IP

Contexto de red

Esta dirección IP pertenece a True Online (AS 17552), que gestiona 12 direcciones IP en nuestro sistema de monitorización. De ellas, 519 han sido señaladas por actividades sospechosas, lo que ha dado lugar a un nivel de amenaza para toda la red de 3 /10.

Estado de la red: Esta red parece estar bien mantenida y presenta bajos indicadores de amenaza.

Análisis comparativo

Cómo se compara esta dirección IP con otras de nuestra base de datos de Threat Intelligence

93 %

Clasificación mundial de amenazas

Esta dirección IP es más peligrosa que 93 % de todas las direcciones IP de nuestra base de datos.

El 10 % más peligroso

Comparación mundial

Comparado con las direcciones IP registradas en todo el mundo en 312.325

Nivel de amenaza 10/10 promedio: 6,0 ++
Total Reports 497 promedio: 18 ++

Comparación de redes

Comparado con las direcciones IP 181 del ASN 17552

Nivel de amenaza 10/10 Promedio de la red: 5,6 ++
Total Reports 497 Promedio de la red: 4 ++
La red True Online tiene un nivel de amenaza global de 3 /10

Comparación geográfica

Comparado con las direcciones IP de 2.239 en TH

Nivel de amenaza 10/10 Media nacional: 5,5 ++
Total Reports 497 Media nacional: 12 ++
Indicadores:
++ Mucho más alto + Más alto = Similar - Inferior -- Mucho más bajo

Distribución geográfica de las amenazas

292.711 incidentes de amenazas registrados a nivel mundial • Últimas 24 horas: 17.660 Registros

FEED

Principales fuentes de amenazas

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 más países

NIVEL DE AMENAZA
BAJO MED ALTO

Los datos geográficos se agrupan y se anonimizan. No se muestra ninguna información personal.

Mapa: simplemaps.com (MIT License)

IP relacionadas

Otras direcciones IP asociadas a esta dirección por similitud de red o de comportamiento

Direcciones IP del mismo proveedor de red del sistema autónomo (AS).

20 IP relacionadas
7.7/10 Amenaza media
48% Confianza media
19 Alto riesgo
Red de alto riesgo: la mayoría de las direcciones IP relacionadas están marcadas
171.97.32.185 10/10
Confianza 84%
Reports 9
Ubicación TH TH
171.96.136.25 10/10
Confianza 62%
Reports 5
Ubicación TH TH
124.121.93.133 10/10
Confianza 57%
Reports 6
Ubicación TH TH
110.168.24.174 10/10
Confianza 55%
Reports 4
Ubicación TH TH
2001:fb1:c4:a36c:58e6:d0c6:2062:987a 8/10
Confianza 53%
Reports 3
Ubicación TH TH
124.121.95.192 10/10
Confianza 51%
Reports 3
Ubicación TH TH
110.171.151.15 8/10
Confianza 49%
Reports 13
Ubicación TH TH
171.97.76.35 8/10
Confianza 49%
Reports 5
Ubicación TH TH
2001:fb1:167:cad3:e141:b6c0:8fe7:85ff 8/10
Confianza 49%
Reports 3
Ubicación TH TH
124.121.30.254 0/10
Confianza 46%
Reports 3
Ubicación TH TH
110.171.180.167 8/10
Confianza 44%
Reports 3
Ubicación TH TH
2001:fb1:c6:160:ccc6:c91f:dc8c:b30a 7/10
Confianza 40%
Reports 2
Ubicación TH TH
2001:fb1:165:8d50:6064:caf0:1220:fe97 7/10
Confianza 40%
Reports 2
Ubicación TH TH
2001:fb1:15d:3acc:c531:9987:fab1:7c6a 7/10
Confianza 40%
Reports 2
Ubicación TH TH
2001:fb1:14e:1d4d:d175:cf69:c40e:d6f3 7/10
Confianza 40%
Reports 2
Ubicación TH TH
2001:fb1:c5:3fd4:bda4:c25b:dae0:8b54 7/10
Confianza 40%
Reports 2
Ubicación TH TH
171.97.0.64 7/10
Confianza 40%
Reports 2
Ubicación TH TH
2001:fb1:14f:9559:c927:25c9:deb5:cf6a 7/10
Confianza 40%
Reports 2
Ubicación TH TH
171.97.0.207 7/10
Confianza 40%
Reports 2
Ubicación TH TH
124.121.30.19 7/10
Confianza 40%
Reports 2
Ubicación TH TH

Reglas de exportación y Firewall Rules

Descarga datos sobre amenazas o genera Firewall Rules para bloquear esta IP

Informe JSON

Formato de datos estructurados para la integración con herramientas de seguridad y sistemas SIEM.

{
    "ip_address": "58.9.10.203",
    "threat_level": 10,
    "confidence_score": 64,
    "total_reports": 497,
    "country_code": "TH",
    "isp_name": "True Online",
    "asn": "17552",
    "first_reported": "2025-09-28 13:51:34",
    "last_reported": "2025-11-08 04:57:34",
    "exported_at": "2026-08-06T17:57:30+02:00",
    "source": "https://reportedip.com/ip/58.9.10.203/"
}

GDPR Compliant: Las exportaciones contienen únicamente datos sobre amenazas relacionados con direcciones IP. No se incluye ninguna información personal ni datos del informante.