Critical Threat
IP 195.96.143.125 is a critical-risk address associated with an exploited host originating from West-TV LLC's network in Ukraine, presenting a severe and active threat that demands immediate defensive action.
Automated honeypot sensors across the community flagged this address 180 times, with 20 of the most recent reports specifically categorising the activity as an exploited host — a classification indicating the IP belongs to a system that has been compromised and is now being weaponised by threat actors without the legitimate owner's knowledge. All detections originated from automated honeypot infrastructure between October and November 2025, and while the activity frequency metric shows minimal recent engagement, the sheer volume of historical reports combined with a maximum threat-level rating of 10 out of 10 confirms a persistent and dangerous compromise. The network operator, West-TV LLC, operates under ASN AS211621, and the moderate 67% confidence score suggests that while the exploited-host classification is well-supported, some contextual ambiguity remains about the full scope of the malicious activity originating from this address.
An exploited host represents one of the most dangerous categories in threat intelligence because the compromised machine functions as a unwitting launchpad for further attacks — the owner has no awareness of the compromise and therefore cannot remediate it. Malware and exploit payloads detected on this host could be leveraged for distributed denial-of-service campaigns, credential stuffing against external services, lateral movement within partner networks, or serving as a command-and-control relay. Because the source IP appears to belong to a legitimate Ukrainian network subscriber, traffic originating from it may bypass basic IP reputation filters that rely solely on geographic or ASN blocklists.
Site operators should block 195.96.143.125 at the firewall or edge security layer immediately and monitor inbound traffic for any remaining probes from this address. Implementing fail2ban, CrowdSec, or similar dynamic blocking tools can automate this response and reduce manual intervention. Reach out to West-TV LLC or the relevant Ukrainian Computer Emergency Response Team to report the compromised system so the legitimate owner can be notified and the infection remediated at the source. Finally, review authentication logs for any successful or attempted connections originating from this IP range to identify potential credential exposure or successful intrusions.