IP Address

103.171.188.76

IPv4 Public
IN IN
AS139543
MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED
253 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
1% Confidence
253 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
IN
IN Location
MAHABAL NET SERVICE PROVI... ASN 139543
253 Reports
Honeypot Data Source

Severe Risk

IP 103.171.188.76 is a maximum-risk address linked to sustained SSH brute-force and hacking activity, with 253 abuse reports filed against this Indian IP originating from MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED infrastructure between February and March 2026.

The evidence base for this threat assessment draws from 20 automated honeypot sensors that detected Suricata alerts flagging active SSH brute-force attempts and confirmed attack connections originating from this address. While the confidence score stands at 64%, the sheer volume of reports combined with the 10/10 threat level designation paints a concerning picture. The activity window spans February through March 2026, indicating a deliberate, persistent campaign rather than transient scanning. Geographically located in India and operating through AS139543, this IP represents infrastructure within a commercial service provider network that is being actively weaponized against SSH services worldwide. The dominant reported category is general hacking activity at 20 instances, supplemented by isolated SSH-specific and exploited-host reports.

SSH brute-force attacks systematically attempt to compromise server credentials by iterating through authentication pairs until access is gained. The real-world risk extends far beyond initial access: once inside, threat actors routinely establish persistent backdoors, exfiltrate data, deploy secondary payloads, or leverage the compromised host as a launchpad for further attacks. The confirmed "Exploited Host" classification suggests this IP may itself be part of a larger compromised infrastructure chain, multiplying its potential impact across multiple targets. The low activity frequency score alongside high report volume indicates this operator favors persistent, low-and-slow attack patterns designed to evade conventional detection thresholds.

Site operators should immediately block 103.171.188.76 at firewall and network perimeter levels. Deploying fail2ban or equivalent intrusion-prevention tools will automatically detect and ban repeated SSH authentication failures from this and similar addresses. Hardening measures including disabling root login, enforcing key-based authentication over passwords, and changing the default SSH port significantly reduce exposure to these credential-guessing campaigns. Ongoing monitoring of authentication logs for patterns associated with this IP remains essential, and if traffic analysis suggests the address belongs to a legitimate Indian business, notifying the hosting provider about the compromise warrants consideration.

More threatening than 91% of monitored IPs

Threat Categories

Hacking 30
Exploited Host 1
SSH 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 139543) with generally good reputation. The ISP MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 1% Low Confidence

Confidence History

7. Feb 2026 - 10. Mar 2026
1% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking SSH Exploited Host Honeypot x3 75%
Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot x3 75%
Hacking Honeypot 75%
Hacking Honeypot x3 75%
Hacking Honeypot x3 75%
Hacking Honeypot x6 75%
Hacking Honeypot x2 75%
Hacking Honeypot x2 75%
Hacking Honeypot x3 75%
Hacking Honeypot 75%
Hacking Honeypot x3 75%
Hacking Honeypot x4 75%
Hacking Honeypot x5 75%
Hacking Honeypot x2 75%
Hacking Honeypot x2 75%
Hacking Honeypot x3 75%
Hacking Honeypot 75%
Hacking Honeypot x3 75%
Hacking Honeypot x2 75%
Hacking Honeypot x7 75%
Hacking Honeypot x2 75%
Hacking Honeypot x2 75%
Hacking Honeypot x3 75%
Hacking Honeypot 75%
Hacking Honeypot x4 75%
Hacking Honeypot x2 75%
Hacking Honeypot x2 75%

Technical Details

Basic Information

IP Address
103.171.188.76
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
IN IN
ASN
AS139543
ISP
MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED

DNS Information

Reverse DNS
nsg-gateway-188.171.103.mahabalnet.in
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
253
First Reported
2 Feb 2026
Last Reported
10 Mar 2026, 17:37

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS139543
MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED
IN IN

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

9
Total IPs Monitored
2,141
Total Reports
237.9
Reports per IP

Network Context

This IP address belongs to MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED (AS139543), which manages 9 IP addresses in our monitoring system. Out of these, 2,141 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

91 %

Global Threat Ranking

This IP is more threatening than 91% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 832,561 reported IPs worldwide

Threat Level 10/10 avg: 6.3 ++
Total Reports 253 avg: 9 ++

Network Comparison

Compared against 21 IPs in ASN 139543

Threat Level 10/10 network avg: 8.3 +
Total Reports 253 network avg: 36 ++
Network MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED has overall threat level 3/10

Geographic Comparison

Compared against 87,172 IPs in IN

Threat Level 10/10 country avg: 6.6 ++
Total Reports 253 country avg: 3 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

756,872 threat incidents tracked globally • Last 24h: 29,621 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    148,132 19.6%
  2. 02
    BR
    Brazil BR
    111,841 14.8%
  3. 03
    IN
    India IN THIS IP
    87,172 11.5%
  4. 04
    CN
    China CN
    46,061 6.1%
  5. 05
    SC
    SC SC
    29,252 3.9%
  6. 06
    DE
    Germany DE
    18,367 2.4%
  7. 07
    NL
    Netherlands NL
    17,978 2.4%
  8. 08
    PK
    Pakistan PK
    17,804 2.4%
  9. 09
    AR
    Argentina AR
    16,266 2.1%
  10. 10
    CO
    Colombia CO
    15,169 2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.3/10 Avg Threat
15% Avg Confidence
16 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "103.171.188.76",
    "threat_level": 10,
    "confidence_score": 1,
    "total_reports": 253,
    "country_code": "IN",
    "isp_name": "MAHABAL NET SERVICE PROVIDER PRIVATE LIMITED",
    "asn": "139543",
    "first_reported": "2026-02-02 09:12:29",
    "last_reported": "2026-03-10 17:37:11",
    "exported_at": "2026-10-07T21:07:19+02:00",
    "source": "https://reportedip.com/ip/103.171.188.76/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.