Dirección IP

62.60.131.157

IPv4 Público
IR IR
Tawsie Technology
4.251 Reports
Esta dirección IP está bajo vigilancia Se ha detectado una actividad sospechosa: vigílala de cerca
10/10 Amenaza
59% Confianza
4.251 Reports

Análisis de Threat Intelligence

Evaluación de seguridad generada por IA basada en datos agregados sobre amenazas

Top 10% High Threat
IR
IR Ubicación
Tawsie Technology ISP
4.251 Reports
Honeypot Fuente de datos

Critical Alert

IP 62.60.131.157 is a maximum-threat-level address originating from Iran that has accumulated 4251 abuse reports across automated honeypot sensors, with recent activity focused on SSH brute-force attempts and broader hacking intrusion patterns. The address presents a severe risk to any publicly accessible SSH service due to its sustained, high-volume automated attack profile detected between September and December 2025.

The data underlying this assessment is substantial and consistent across multiple independent detection points. Twenty separate automated honeypot sensors filed reports against this single address, generating 4251 total abuse reports over a four-month window. While the dominant recent threat category was general hacking activity with 13 reports, SSH-specific intrusion attempts accounted for 7 additional reports, indicating the address is actively engaged in credential-guessing campaigns targeting SSH services. The network operator is identified as Tawsie Technology, and the geographic concentration in Iran provides relevant context for threat-actor attribution and risk prioritization. The moderate 59% confidence score reflects some uncertainty typical in automated threat intelligence, yet the sheer volume of independent sensor reports establishes a reliable threat pattern independent of any single detection source.

SSH brute-force attacks represent one of the most common and effective pathways attackers use to gain unauthorized shell access to servers. These campaigns leverage automated tools that cycle through dictionary wordlists and common credential combinations against exposed SSH daemons, exploiting weak passwords and default configurations. Each successful authentication grants an attacker a persistent foothold, enabling data theft, secondary malware deployment, or lateral movement through a network. The honeypot events specifically indicate the address is part of coordinated scanning infrastructure designed to systematically identify vulnerable targets among internet-facing servers. Organizations running SSH on standard ports with password-based authentication face direct exposure to this class of automated intrusion attempt.

Site operators should treat this IP address as a confirmed hostile source and implement immediate defensive controls. Blocking or rate-limiting traffic from this address at the network perimeter eliminates current exposure. For SSH services specifically, transitioning to key-based authentication eliminates the credential-guessing attack surface that brute-force campaigns exploit. Repositioning SSH to a non-standard port and deploying automated tools such as fail2ban to ban repeated authentication failures after threshold violations provides layered protection against automated scanning. Restricting SSH access to known IP allowlists and disabling root login further harden exposed services against this threat pattern.

Más amenazante que 91 % de direcciones IP supervisadas

Threat Categories

Hacking 19
SSH 11

Detalles técnicos

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Medidas de mitigación recomendadas

Keep systems patched, implement intrusion detection, and follow security best practices.

Cloud Infrastructure

This IP operates from Amazon Web Services (AWS) cloud infrastructure. Cloud-hosted threats can be provisioned and abandoned quickly, affecting attribution.

Cloud-hosted malicious activity often indicates automated or scalable attack infrastructure.

Recomendaciones de seguridad

Continue monitoring for emerging patterns.

Este análisis se genera automáticamente a partir de datos agregados y anonimizados de Threat Intelligence. No se muestra ni se almacena ninguna información personal. La precisión de la evaluación depende del volumen y la diversidad de los datos disponibles.

Reputation Summary

Nivel de amenaza 10/10 Critical
Critical
Frecuencia de la actividad 0/10 Inactive
Confidence Score 59% High Confidence

Confidence History

12. Dic 2025
59% Actual
Stable Tendencia

El Confidence Score indica la fiabilidad de la evaluación de la amenaza en función del número y la calidad de los informes.

Informes de seguridad (30)

Fecha Categorías Fuente Confianza
Hacking Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Detalles técnicos

Información básica

Dirección IP
62.60.131.157
Versión de IP
IPv4
Tipo de red
Público
Red Tor
No
Clase de red
Class A

Geolocalización

País
IR IR
ASN
Desconocido
ISP
Tawsie Technology

Información sobre el DNS

Reverse DNS
Ninguno
Récord en el PTR
No
Tipo de conexión
Estático

Estadísticas

Total Reports
4.251
Publicado por primera vez en Reports
29 Sep 2025
Última actualización de Reports
12 Dic 2025, 05:12

Análisis comparativo

Cómo se compara esta dirección IP con otras de nuestra base de datos de Threat Intelligence

91 %

Clasificación mundial de amenazas

Esta dirección IP es más peligrosa que 91 % de todas las direcciones IP de nuestra base de datos.

El 10 % más peligroso

Comparación mundial

Comparado con las direcciones IP registradas en todo el mundo en 312.426

Nivel de amenaza 10/10 promedio: 6,0 ++
Total Reports 4.251 promedio: 18 ++

Comparación geográfica

Comparado con las direcciones IP de 1.023 en IR

Nivel de amenaza 10/10 Media nacional: 7,3 +
Total Reports 4.251 Media nacional: 36 ++
Indicadores:
++ Mucho más alto + Más alto = Similar - Inferior -- Mucho más bajo

Distribución geográfica de las amenazas

292.711 incidentes de amenazas registrados a nivel mundial • Últimas 24 horas: 17.660 Registros

FEED

Principales fuentes de amenazas

  1. 01
    US
    United States US
    65.787 22.5%
  2. 02
    IN
    India IN
    49.120 16.8%
  3. 03
    CN
    China CN
    35.633 12.2%
  4. 04
    BR
    Brazil BR
    15.556 5.3%
  5. 05
    DE
    Germany DE
    10.500 3.6%
  6. 06
    PK
    Pakistan PK
    8.479 2.9%
  7. 07
    ID
    Indonesia ID
    8.404 2.9%
  8. 08
    SG
    Singapore SG
    8.312 2.8%
  9. 09
    RU
    Russia RU
    6.394 2.2%
  10. 10
    NL
    Netherlands NL
    6.295 2.2%

+40 más países

NIVEL DE AMENAZA
BAJO MED ALTO

Los datos geográficos se agrupan y se anonimizan. No se muestra ninguna información personal.

Mapa: simplemaps.com (MIT License)

IP relacionadas

Otras direcciones IP asociadas a esta dirección por similitud de red o de comportamiento

Direcciones IP del mismo rango de subred, probablemente del mismo segmento de red.

20 IP relacionadas
7.7/10 Amenaza media
81% Confianza media
17 Alto riesgo
Red de alto riesgo: la mayoría de las direcciones IP relacionadas están marcadas

Reglas de exportación y Firewall Rules

Descarga datos sobre amenazas o genera Firewall Rules para bloquear esta IP

Informe JSON

Formato de datos estructurados para la integración con herramientas de seguridad y sistemas SIEM.

{
    "ip_address": "62.60.131.157",
    "threat_level": 10,
    "confidence_score": 59,
    "total_reports": 4251,
    "country_code": "IR",
    "isp_name": "Tawsie Technology",
    "asn": "0",
    "first_reported": "2025-09-29 07:55:58",
    "last_reported": "2025-12-12 05:12:17",
    "exported_at": "2026-08-06T19:22:28+02:00",
    "source": "https://reportedip.com/ip/62.60.131.157/"
}

GDPR Compliant: Las exportaciones contienen únicamente datos sobre amenazas relacionados con direcciones IP. No se incluye ninguna información personal ni datos del informante.