IP Address

192.76.153.253

IPv4 Public Tor Exit Node
NL NL
AS60404
The Infrastructure Group B.V.
218 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
74% Confidence
218 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
NL
NL Location
The Infrastructure Group ... ASN 60404
218 Reports
Mixed Data Source

Notable Threat

IP 192.76.153.253 is a high-risk address operating from The Infrastructure Group B.V. infrastructure in the Netherlands, with 190 total abuse reports and an 8/10 threat level indicating significant malicious activity. The dominant threat profile combines hacking intrusion attempts, SSH brute-force attacks, and port-scanning reconnaissance, suggesting this IP is actively engaged in credential compromise and infrastructure mapping against exposed services worldwide.

Analysis of the 190 reports filed between October 2025 and May 2026 reveals a persistent threat actor detected by 14 automated honeypot sensors and 6 community sources. The report breakdown shows Hacking activity leading at 11 incidents, followed by 6 Brute-Force attempts, 4 Port Scan events, 2 Web App Attack probes, and 1 SSH-specific incident. Detection logs from network security sensors captured Ciscoasa port-scanning probes and Suricata alerts flagging SSH sessions on non-standard ports alongside active brute-force authentication attempts. The 74% confidence score reflects substantial corroborating evidence from multiple independent detection systems, though attribution remains inconclusive. With an activity frequency rated at 4/10, the pattern suggests sustained, deliberate targeting rather than opportunistic scanning bursts.

The combined Hacking and Brute-Force activity represents a concrete authentication bypass risk for any exposed SSH, web application, or remote administration interfaces. Port-scanning behavior indicates the operator is systematically cataloguing open services as preparation for follow-on exploitation, while web application probes suggest interest in vulnerable web-facing assets. The presence of Suricata alerts confirming active SSH sessions on unexpected ports points to either compromised legitimate traffic or encrypted tunneled connections being established from this address. Organizations with weak or default credentials on exposed services face immediate account compromise risk if this IP is permitted access.

Site operators should block IP 192.76.153.253 at the network perimeter firewall and implement fail2ban or equivalent log-analysis tools to automatically ban repeated authentication failures. Enforcing multi-factor authentication on all remote access services eliminates the primary attack surface that brute-force campaigns target. Rate-limiting authentication endpoints and applying account lockout policies after failed attempts further disrupts automated credential stuffing. Regular monitoring of access logs for connections originating from this address and maintaining intrusion detection signatures for the observed scanning patterns will strengthen defensive posture against similar reconnaissance activity.

More threatening than 90% of monitored IPs

Threat Categories

Brute-Force 15
Hacking 11
Port Scan 3
WP User Enumeration 2
Exploited Host 2
Blog Spam 1

Technical Details

Brute-force attacks systematically attempt password combinations against authentication systems.

Recommended Mitigations

Implement rate limiting, account lockout policies, multi-factor authentication, and fail2ban.

Behavioral Analysis

Activity Pattern: Consistent Activity

Steady malicious activity over 3 weeks indicates persistent threat actor operations.

First Observed 8. September 2026
Last Activity 29. September 2026
Recent (7 days) 2 incidents

Reputable Network

This IP is hosted on a network (ASN 60404) with generally good reputation. The ISP The Infrastructure Group B.V. maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Long-term blocking recommended.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 3/10 Low
Confidence Score 74% High Confidence

Confidence History

29. May 2026 - 1. Oct 2026
74% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Blog Spam Community 75%
WP User Enumeration Community 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
WP REST API Abuse Community 75%
Hacking SSH Honeypot x2 75%
Port Scan Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking DDoS Attack Community 75%
Hacking Honeypot 75%
Brute-Force Community 75%
WP User Enumeration Community 75%
Hacking Honeypot 75%
Brute-Force Community 75%
Port Scan Hacking Exploited Host +1 Honeypot x4 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Hacking Honeypot 75%
Port Scan Hacking Exploited Host Honeypot x3 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%

Technical Details

Basic Information

IP Address
192.76.153.253
IP Version
IPv4
Network Type
Public
Tor Network
Tor Exit Node
Network Class
Class C

Geolocation

Country
NL NL
ASN
AS60404
ISP
The Infrastructure Group B.V.

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
218
First Reported
9 Oct 2025
Last Reported
1 Oct 2026, 00:50

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS60404
The Infrastructure Group B.V.
NL NL

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

21
Total IPs Monitored
539
Total Reports
25.7
Reports per IP

Network Context

This IP address belongs to The Infrastructure Group B.V. (AS60404), which manages 21 IP addresses in our monitoring system. Out of these, 539 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

90 %

Global Threat Ranking

This IP is more threatening than 90% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 806,592 reported IPs worldwide

Threat Level 8/10 avg: 6.3 +
Total Reports 218 avg: 9 ++

Network Comparison

Compared against 61 IPs in ASN 60404

Threat Level 8/10 network avg: 7.5 =
Total Reports 218 network avg: 12 ++
Network The Infrastructure Group B.V. has overall threat level 3/10

Geographic Comparison

Compared against 17,473 IPs in NL

Threat Level 8/10 country avg: 6.3 +
Total Reports 218 country avg: 30 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

733,504 threat incidents tracked globally • Last 24h: 28,676 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    143,262 19.5%
  2. 02
    BR
    Brazil BR
    110,751 15.1%
  3. 03
    IN
    India IN
    82,121 11.2%
  4. 04
    CN
    China CN
    44,763 6.1%
  5. 05
    SC
    SC SC
    29,233 4%
  6. 06
    DE
    Germany DE
    17,490 2.4%
  7. 07
    NL
    Netherlands NL THIS IP
    17,472 2.4%
  8. 08
    PK
    Pakistan PK
    16,640 2.3%
  9. 09
    AR
    Argentina AR
    16,189 2.2%
  10. 10
    CO
    Colombia CO
    15,134 2.1%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
7.3/10 Avg Threat
37% Avg Confidence
12 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "192.76.153.253",
    "threat_level": 8,
    "confidence_score": 74,
    "total_reports": 218,
    "country_code": "NL",
    "isp_name": "The Infrastructure Group B.V.",
    "asn": "60404",
    "first_reported": "2025-10-09 06:20:15",
    "last_reported": "2026-10-01 00:50:29",
    "exported_at": "2026-10-01T01:52:13+02:00",
    "source": "https://reportedip.com/ip/192.76.153.253/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.