IP Address

138.226.239.91

IPv4 Public
GB GB
AS213474
HomeLine Broadband LLC
1,074 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
91% Confidence
1,074 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
GB
United Kingdom Location
HomeLine Broadband LLC ASN 213474
1,074 Reports
Honeypot Data Source

Substantial Risk

IP 138.226.239.91 is a high-risk address associated with aggressive reconnaissance activity, having accumulated 1,000 abuse reports within a two-month window and scoring 8 out of 10 for threat severity. The dominant threat profile centers on automated port-scanning behavior detected by honeypot sensors, indicating systematic probing of exposed network services as a precursor to potential intrusion attempts. With a confidence score of 91 percent, analysts can place substantial reliance on the malicious classification of this endpoint.

The IP originates from HomeLine Broadband LLC operating within AS213474 and routing through United Kingdom infrastructure, presenting a substantial threat vector due to its concentrated attack pattern. Over approximately eight weeks spanning July and August 2026, honeypot sensors documented consistent scanning behavior, with 20 recent reports specifically flagging port-scan activity including Ciscoasa reconnaissance probes. The sustained volume of 1,000 total reports against an 8 out of 10 activity frequency signals persistent, high-intensity scanning operations rather than isolated probing events.

Port scanning represents a critical reconnaissance phase in the attack lifecycle, enabling threat actors to map network topologies, identify running services, and select viable entry points for subsequent exploitation attempts. The specific Ciscoasa probe pattern observed suggests targeting of perimeter security appliances, potentially seeking vulnerabilities in firewall or VPN infrastructure. Organizations with exposed management interfaces or unpatched edge devices face elevated risk should this reconnaissance inform follow-on attacks.

Network defenders should implement strict ingress filtering to block traffic originating from this address, deploy rate-limiting on authentication endpoints, and utilize intrusion detection systems to identify scanning patterns. Implementing fail2ban or equivalent log-analysis tools can automatically mitigate repeated probe attempts, while regular audit of exposed service inventory reduces the attack surface available to reconnaissance operations.

More threatening than 85% of monitored IPs

Threat Categories

Port Scan 30

Technical Details

Port scanning identifies open services and potential attack vectors on target systems as reconnaissance for attacks.

Recommended Mitigations

Minimize exposed services, implement firewall rules, and monitor for scanning patterns.

Behavioral Analysis

Activity Pattern: Sporadic

Irregular burst activity pattern indicates intermittent use of a compromised system.

First Observed 21. July 2026
Last Activity 6. August 2026
Recent (7 days) 449 incidents

Reputable Network

This IP is hosted on a network (ASN 213474) with generally good reputation. The ISP HomeLine Broadband LLC maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Implement adaptive blocking rules.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 91% Verified

Confidence History

6. Aug 2026
91% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%
New Port Scan Honeypot 75%

Technical Details

Basic Information

IP Address
138.226.239.91
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
GB GB
ASN
AS213474
ISP
HomeLine Broadband LLC

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
1,074
First Reported
21 Jul 2026
Last Reported
6 Aug 2026, 18:35

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS213474
HomeLine Broadband LLC
FI FI

Network Threat Assessment

2/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

3
Total IPs Monitored
3
Total Reports
1
Reports per IP

Network Context

This IP address belongs to HomeLine Broadband LLC (AS213474), which manages 3 IP addresses in our monitoring system. Out of these, 3 have been reported for suspicious activities, resulting in a network-wide threat level of 2/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

85 %

Global Threat Ranking

This IP is more threatening than 85% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 312,366 reported IPs worldwide

Threat Level 8/10 avg: 6.0 +
Total Reports 1,074 avg: 18 ++

Network Comparison

Compared against 13 IPs in ASN 213474

Threat Level 8/10 network avg: 8.8 =
Total Reports 1,074 network avg: 194 ++
Network HomeLine Broadband LLC has overall threat level 2/10

Geographic Comparison

Compared against 6,125 IPs in GB

Threat Level 8/10 country avg: 6.0 +
Total Reports 1,074 country avg: 24 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

292,711 threat incidents tracked globally • Last 24h: 17,660 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    65,787 22.5%
  2. 02
    IN
    India IN
    49,120 16.8%
  3. 03
    CN
    China CN
    35,633 12.2%
  4. 04
    BR
    Brazil BR
    15,556 5.3%
  5. 05
    DE
    Germany DE
    10,500 3.6%
  6. 06
    PK
    Pakistan PK
    8,479 2.9%
  7. 07
    ID
    Indonesia ID
    8,404 2.9%
  8. 08
    SG
    Singapore SG
    8,312 2.8%
  9. 09
    RU
    Russia RU
    6,394 2.2%
  10. 10
    NL
    Netherlands NL
    6,295 2.2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "138.226.239.91",
    "threat_level": 8,
    "confidence_score": 91,
    "total_reports": 1074,
    "country_code": "GB",
    "isp_name": "HomeLine Broadband LLC",
    "asn": "213474",
    "first_reported": "2026-07-21 16:08:20",
    "last_reported": "2026-08-06 18:35:07",
    "exported_at": "2026-08-06T18:39:44+02:00",
    "source": "https://reportedip.com/ip/138.226.239.91/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.