IP Address

193.104.222.2

IPv4 Public
GB GB
AS42201
PVDataNet AB
177 Reports
This IP is under Observation Suspicious activity detected - monitor closely
7/10 Threat
4% Confidence
177 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Moderate Risk
GB
GB Location
PVDataNet AB ASN 42201
177 Reports
Honeypot Data Source

Substantial Risk

IP 193.104.222.2 is a moderate-to-high-risk address associated with VoIP fraud activity, with 177 abuse reports submitted through automated honeypot sensors between March and May 2026. The IP has been flagged with a threat level of 7/10 and a confidence score of 87%, indicating a reliable correlation between the observed behavior and the reported threat category.

The IP is geolocated to Great Britain and operates within AS42201, administered by PVDataNet AB. Across the two-month reporting window, automated honeypot sensors submitted 20 reports specifically categorizing the activity as Fraud VoIP, representing the dominant threat type among all submissions. The activity frequency has been assessed at 4/10, suggesting persistent but not hyperactive engagement. With 177 total reports and 20 dedicated VoIP fraud reports, this address demonstrates a consistent pattern of abuse that warrants attention from network defenders.

VoIP fraud exploits voice-over-internet-protocol systems to make unauthorized calls, typically to premium-rate numbers or international destinations, generating illicit revenue for threat actors. The concrete risk to an exposed VoIP service includes financial losses from fraudulent call charges, resource consumption by unauthorized traffic, and potential reputational damage if the compromised system is used to relay calls for illegal operations. Organizations with exposed SIP ports, weak authentication on VoIP infrastructure, or unrestricted international/premium dialing routes are particularly vulnerable to this type of exploitation.

Site operators should take immediate defensive action. Implementing strong authentication mechanisms such as SIP ALG-aware credentials, TLS encryption, and IP allowlisting significantly reduces unauthorized access. Configuring fail2ban or similar intrusion-prevention tools to monitor and block repeated authentication failures can disrupt automated attack workflows. Restricting international and premium-rate dialing capabilities, enabling call pattern monitoring for anomalies, and deploying session-border controllers to validate call authorization represent additional layers of protection against this threat vector.

More threatening than 70% of monitored IPs

Threat Categories

Fraud VoIP 30

Technical Details

VoIP fraud exploits phone systems to make unauthorized calls, often to premium rate numbers for financial gain.

Recommended Mitigations

Implement call authentication, monitor call patterns, and restrict international/premium rate dialing.

Reputable Network

This IP is hosted on a network (ASN 42201) with generally good reputation. The ISP PVDataNet AB maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 7/10 High
High
Activity Frequency 0/10 Inactive
Confidence Score 3% Low Confidence

Confidence History

20. Mar 2026 - 17. May 2026
4% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%

Technical Details

Basic Information

IP Address
193.104.222.2
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
GB GB
ASN
AS42201
ISP
PVDataNet AB

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
177
First Reported
19 Mar 2026
Last Reported
17 May 2026, 09:32

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS42201
PVDataNet AB
GB GB

Network Threat Assessment

0/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

28
Total IPs Monitored
515
Total Reports
18.4
Reports per IP

Network Context

This IP address belongs to PVDataNet AB (AS42201), which manages 28 IP addresses in our monitoring system. Out of these, 515 have been reported for suspicious activities, resulting in a network-wide threat level of 0/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

70 %

Global Threat Ranking

This IP is more threatening than 70% of all IPs in our database.

Above Average Threat

Global Comparison

Compared against 850,185 reported IPs worldwide

Threat Level 7/10 avg: 6.3 =
Total Reports 177 avg: 9 ++

Network Comparison

Compared against 44 IPs in ASN 42201

Threat Level 7/10 network avg: 6.5 =
Total Reports 177 network avg: 21 ++
Network PVDataNet AB has overall threat level 0/10

Geographic Comparison

Compared against 11,121 IPs in GB

Threat Level 7/10 country avg: 7.1 =
Total Reports 177 country avg: 17 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

772,738 threat incidents tracked globally • Last 24h: 28,099 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    150,913 19.5%
  2. 02
    BR
    Brazil BR
    112,902 14.6%
  3. 03
    IN
    India IN
    89,952 11.6%
  4. 04
    CN
    China CN
    46,596 6%
  5. 05
    SC
    SC SC
    29,267 3.8%
  6. 06
    DE
    Germany DE
    18,856 2.4%
  7. 07
    PK
    Pakistan PK
    18,396 2.4%
  8. 08
    NL
    Netherlands NL
    18,286 2.4%
  9. 09
    AR
    Argentina AR
    16,707 2.2%
  10. 10
    CO
    Colombia CO
    15,365 2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
6.9/10 Avg Threat
6% Avg Confidence
17 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
6.7/10 Avg Threat
1% Avg Confidence
13 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "193.104.222.2",
    "threat_level": 7,
    "confidence_score": 4,
    "total_reports": 177,
    "country_code": "GB",
    "isp_name": "PVDataNet AB",
    "asn": "42201",
    "first_reported": "2026-03-19 01:29:33",
    "last_reported": "2026-05-17 09:32:00",
    "exported_at": "2026-10-11T11:28:41+02:00",
    "source": "https://reportedip.com/ip/193.104.222.2/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.