IP Address

199.45.154.156

IPv4 Public
US US
AS398722
CENSYS-ARIN-03
330 Reports
This IP is under Observation Suspicious activity detected - monitor closely
8/10 Threat
22% Confidence
330 Reports
Is this your IP address? If the cause is fixed, you can request removal. Free of charge, usually decided within 48 hours. Request delisting

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
US
US Location
CENSYS-ARIN-03 ASN 398722
330 Reports
Honeypot Data Source

Notable Threat

IP 199.45.154.156 is a high-risk address originating from the United States that has accumulated 304 total reports across automated honeypot sensors since October 2025, with a current threat level of 8/10 indicating significant malicious activity. The dominant threat category is general hacking activity, accounting for the majority of recent reports, supplemented by smaller volumes of exploited-host and IoT-targeted incidents. With a confidence score of 71%, there is reasonable certainty that this IP poses a genuine threat rather than a false positive.

The IP is registered to network operator CENSYS-ARIN-03 within ASN AS398722 and has been tracked for approximately seven months, with the most recent activity occurring in May 2026. Detection sources exclusively comprise 20 automated honeypot sensors, which flagged repeated attack patterns consistent with connection attempts, IoT and industrial control system targeting, and broader malware or exploit activity. The activity frequency rating of 3/10 suggests persistent but not excessively high-volume behavior, likely representing targeted probing rather than bulk scanning. The combination of 304 total reports against this modest activity rate indicates a sustained, methodical threat presence rather than opportunistic noise.

The primary hacking activity associated with this IP aligns with general intrusion attempts, vulnerability exploitation, and unauthorized access attempts against exposed services. The presence of IoT-targeted reports suggests this address may be conducting reconnaissance or exploitation against poorly secured connected devices, industrial systems, or smart infrastructure. The exploited-host reports indicate that either this IP itself is operating from a compromised system or it is targeting compromised infrastructure, raising questions about its operational autonomy. Together, these patterns suggest an actor engaged in persistent probing of internet-facing systems with particular interest in IoT and ICS environments, potentially deploying malware or exploiting known vulnerabilities to establish footholds.

Site operators should block IP 199.45.154.156 at the firewall or network edge to prevent direct connection attempts. Implementing fail2ban or similar intrusion-prevention tools can automatically detect and respond to the observed attack patterns. Exposed services should be audited for vulnerabilities, especially those affecting IoT and industrial control systems, and unneeded services should be disabled to reduce attack surface. Continuous monitoring with updated threat-intelligence feeds will help maintain protection as this IP's activity evolves.

More threatening than 87% of monitored IPs

Threat Categories

Hacking 26
Port Scan 2
Exploited Host 1
Bad Web Bot 1
WP Fake SEO Bot 1
IoT Targeted 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 398722) with generally good reputation. The ISP CENSYS-ARIN-03 maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 0/10 Inactive
Confidence Score 21% Low Confidence

Confidence History

23. May 2026 - 30. Jul 2026
22% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Honeypot 75%
Hacking Honeypot 75%
Port Scan Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Port Scan Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Bad Web Bot WP Fake SEO Bot Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
IoT Targeted Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
199.45.154.156
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
US US
ASN
AS398722
ISP
CENSYS-ARIN-03

DNS Information

Reverse DNS
156.154.45.199.censys-scanner.com
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
330
First Reported
6 Oct 2025
Last Reported
30 Jul 2026, 20:07

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS398722
Censys, Inc.
US US

Network Threat Assessment

1/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

148
Total IPs Monitored
4,699
Total Reports
31.8
Reports per IP

Network Context

This IP address belongs to Censys, Inc. (AS398722), which manages 148 IP addresses in our monitoring system. Out of these, 4,699 have been reported for suspicious activities, resulting in a network-wide threat level of 1/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

87 %

Global Threat Ranking

This IP is more threatening than 87% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 805,953 reported IPs worldwide

Threat Level 8/10 avg: 6.3 +
Total Reports 330 avg: 9 ++

Network Comparison

Compared against 241 IPs in ASN 398722

Threat Level 8/10 network avg: 8.1 =
Total Reports 330 network avg: 49 ++
Network CENSYS-ARIN-03 has overall threat level 1/10

Geographic Comparison

Compared against 143,148 IPs in US

Threat Level 8/10 country avg: 6.8 +
Total Reports 330 country avg: 18 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

732,959 threat incidents tracked globally • Last 24h: 29,233 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    143,148 19.5%
  2. 02
    BR
    Brazil BR
    110,706 15.1%
  3. 03
    IN
    India IN
    82,092 11.2%
  4. 04
    CN
    China CN
    44,715 6.1%
  5. 05
    SC
    SC SC
    29,233 4%
  6. 06
    DE
    Germany DE
    17,451 2.4%
  7. 07
    NL
    Netherlands NL
    17,448 2.4%
  8. 08
    PK
    Pakistan PK
    16,608 2.3%
  9. 09
    AR
    Argentina AR
    16,188 2.2%
  10. 10
    CO
    Colombia CO
    15,132 2.1%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.6/10 Avg Threat
95% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
9.3/10 Avg Threat
94% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "199.45.154.156",
    "threat_level": 8,
    "confidence_score": 22,
    "total_reports": 330,
    "country_code": "US",
    "isp_name": "CENSYS-ARIN-03",
    "asn": "398722",
    "first_reported": "2025-10-06 21:31:00",
    "last_reported": "2026-07-30 20:07:36",
    "exported_at": "2026-09-30T20:49:47+02:00",
    "source": "https://reportedip.com/ip/199.45.154.156/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.