IP Address

195.96.138.179

IPv4 Public
GB GB
AS210924
ssd networks limited
624 Reports
This IP is under Observation Suspicious activity detected - monitor closely
7/10 Threat
3% Confidence
624 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Moderate Risk
GB
GB Location
ssd networks limited ASN 210924
624 Reports
Honeypot Data Source

Notable Threat

IP 195.96.138.179, registered to ssd networks limited in the United Kingdom and operating on AS210924, presents a high-risk threat profile with a 7/10 threat level and a 91% confidence score. This address has generated 624 total abuse reports with an activity frequency rated 8/10, indicating sustained and persistent hostile behavior. The dominant threat category driving this assessment is VoIP fraud, detected through 20 recent automated honeypot reports filed over an eight-week window between April and May 2026.

The concentration of recent reports from honeypot sensors confirms that IP 195.96.138.179 is actively engaged in VoIP-related exploitation attempts. With 624 cumulative reports and an activity frequency score of 8/10, this address demonstrates consistent scanning and probing behavior targeting voice-over-internet-protocol infrastructure. The geographic location in the United Kingdom and its association with AS210924 operated by ssd networks limited places this source within a commercial hosting environment that may be leveraged for telephony fraud campaigns. The detection span from April through May 2026 indicates the malicious activity is ongoing and has not subsided, maintaining its threat relevance through the present period.

VoIP fraud represents a serious financial threat vector where attackers exploit internet telephone systems to route unauthorized calls, frequently targeting premium-rate numbers to generate illicit revenue. For organizations running exposed SIP (Session Initiation Protocol) servers, telephony gateways, or soft-switches, an address with this threat profile poses a direct risk of toll fraud, service theft, and unauthorized call origination. Attackers leveraging compromised VoIP infrastructure can accumulate substantial charges within minutes, creating immediate financial liability for the victim while obscuring the attacker's identity through this UK-based intermediate address.

Network operators should immediately block IP 195.96.138.179 at the firewall level and implement geographic or rate-based restrictions on outbound SIP traffic. Deploying fail2ban or equivalent intrusion-prevention tools configured to detect and ban brute-force SIP authentication attempts provides an additional defensive layer. Organizations running VoIP services should enforce strong SIP authentication credentials, enable call-pattern monitoring to flag anomalies such as unusual destination numbers or call volumes, and restrict international and premium-rate dialing by default unless explicitly permitted for specific accounts.

More threatening than 69% of monitored IPs

Threat Categories

Fraud VoIP 30

Technical Details

VoIP fraud exploits phone systems to make unauthorized calls, often to premium rate numbers for financial gain.

Recommended Mitigations

Implement call authentication, monitor call patterns, and restrict international/premium rate dialing.

Moderate Network Risk

The network hosting this IP (ASN 210924, operated by ssd networks limited) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 7/10 High
High
Activity Frequency 0/10 Inactive
Confidence Score 3% Low Confidence

Confidence History

13. May 2026
3% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%
Fraud VoIP Honeypot 75%

Technical Details

Basic Information

IP Address
195.96.138.179
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
GB GB
ASN
AS210924
ISP
ssd networks limited

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
624
First Reported
20 Apr 2026
Last Reported
13 May 2026, 13:22

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS210924
ssd networks limited
GB GB

Network Threat Assessment

5/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

8
Total IPs Monitored
421
Total Reports
52.6
Reports per IP

Network Context

This IP address belongs to ssd networks limited (AS210924), which manages 8 IP addresses in our monitoring system. Out of these, 421 have been reported for suspicious activities, resulting in a network-wide threat level of 5/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

69 %

Global Threat Ranking

This IP is more threatening than 69% of all IPs in our database.

Above Average Threat

Global Comparison

Compared against 805,472 reported IPs worldwide

Threat Level 7/10 avg: 6.3 =
Total Reports 624 avg: 9 ++

Network Comparison

Compared against 20 IPs in ASN 210924

Threat Level 7/10 network avg: 8.0 =
Total Reports 624 network avg: 67 ++
Network ssd networks limited has overall threat level 5/10

Geographic Comparison

Compared against 10,261 IPs in GB

Threat Level 7/10 country avg: 7.1 =
Total Reports 624 country avg: 18 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

732,564 threat incidents tracked globally • Last 24h: 28,865 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    143,097 19.5%
  2. 02
    BR
    Brazil BR
    110,689 15.1%
  3. 03
    IN
    India IN
    82,024 11.2%
  4. 04
    CN
    China CN
    44,688 6.1%
  5. 05
    SC
    SC SC
    29,232 4%
  6. 06
    NL
    Netherlands NL
    17,444 2.4%
  7. 07
    DE
    Germany DE
    17,413 2.4%
  8. 08
    PK
    Pakistan PK
    16,575 2.3%
  9. 09
    AR
    Argentina AR
    16,184 2.2%
  10. 10
    CO
    Colombia CO
    15,130 2.1%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "195.96.138.179",
    "threat_level": 7,
    "confidence_score": 3,
    "total_reports": 624,
    "country_code": "GB",
    "isp_name": "ssd networks limited",
    "asn": "210924",
    "first_reported": "2026-04-20 16:15:55",
    "last_reported": "2026-05-13 13:22:14",
    "exported_at": "2026-09-30T18:39:10+02:00",
    "source": "https://reportedip.com/ip/195.96.138.179/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.