IP Address

45.198.224.5

IPv4 Public
US US
AS215925
Vpsvault.host Ltd
1,947 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
94% Confidence
1,947 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
US
United States Location
Vpsvault.host Ltd ASN 215925
1,947 Reports
Mixed Data Source

Significant Threat

IP 45.198.224.5, operated by Vpsvault.host Ltd and routed through AS215925 in the United States, is a high-risk address with a threat level of 8/10 and a 95% confidence score, linked primarily to automated hacking probes, credential-scanning activity, and aggressive bot behavior detected across 1,940 separate incident reports from both honeypot sensors and community sources between May and August 2026.

The sustained volume of 1,940 reports over approximately four months reflects an ongoing, systematic campaign rather than opportunistic scanning, with an activity frequency rated 8/10 indicating persistent engagement with target infrastructure. Detection sources include 9 automated honeypot sensors and 11 community-based abuse reports, validating the findings across multiple independent monitoring systems. The reported threat categories consistently point toward authentication endpoint probing, web application vulnerability scanning, and suspicious automated HTTP client traffic using the Go-http-client user agent, alongside port-scan activity and specific probes for login and authentication paths.

The dominant hacking activity, representing the largest share of reports, signals an actor systematically mapping web-facing authentication interfaces and testing for vulnerable endpoints, while the concurrent bad-web-bot and SEO-bot signatures suggest the infrastructure may serve dual purposes including content scraping and search-engine manipulation schemes. The detection of an SSH session in progress on an expected port further indicates the host is actively maintaining interactive access capabilities, likely leveraging compromised credentials or brute-force techniques against exposed SSH services. This combination of automated probing, authentication-path scanning, and persistent presence creates a concrete risk of unauthorized access, credential compromise, or data exfiltration for any organization running exposed web login portals, SSH daemons, or content-management systems.

Site operators should immediately block or rate-limit this IP at the firewall or load-balancer level, enforce strong multi-factor authentication on all administrative and user-facing login interfaces, and implement bot-detection controls that specifically identify and throttle Go-http-client traffic and other non-browser automated clients. Deploying fail2ban or equivalent dynamic firewall rules on SSH services reduces the risk from credential-brute-force attempts, while web application firewalls configured to flag path-probing behavior on authentication endpoints provide an additional layer of defense against the scanning patterns observed from this source.

More threatening than 85% of monitored IPs

Threat Categories

Hacking 21
Bad Web Bot 18
WP Fake SEO Bot 18
Port Scan 12
Web App Attack 3

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Sporadic

Irregular burst activity pattern indicates intermittent use of a compromised system.

First Observed 8. July 2026
Last Activity 5. August 2026
Recent (7 days) 16 incidents

Reputable Network

This IP is hosted on a network (ASN 215925) with generally good reputation. The ISP Vpsvault.host Ltd maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Implement adaptive blocking rules.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 93% Verified

Confidence History

27. Jul 2026 - 5. Aug 2026
94% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Port Scan Hacking Bad Web Bot +1 Community 75%
Bad Web Bot WP Fake SEO Bot Community 75%
Port Scan Hacking Bad Web Bot +1 Community 75%
Bad Web Bot WP Fake SEO Bot Community 75%
Port Scan Hacking Bad Web Bot +1 Community 75%
Bad Web Bot WP Fake SEO Bot Community x2 75%
Port Scan Hacking Bad Web Bot +1 Community 75%
Bad Web Bot WP Fake SEO Bot Community 75%
Bad Web Bot WP Fake SEO Bot Port Scan +1 Community x2 75%
Bad Web Bot WP Fake SEO Bot Port Scan +1 Community x2 75%
Port Scan Hacking Bad Web Bot +1 Community x3 75%
Bad Web Bot WP Fake SEO Bot Community 75%
Port Scan Hacking Bad Web Bot +1 Community x2 75%
Port Scan Hacking Bad Web Bot +1 Community x3 75%
Port Scan Hacking Bad Web Bot +1 Community x2 75%
Bad Web Bot WP Fake SEO Bot Community 75%
Port Scan Hacking Bad Web Bot +1 Community 75%
Port Scan Hacking Bad Web Bot +1 Community 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%

Technical Details

Basic Information

IP Address
45.198.224.5
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS215925
ISP
Vpsvault.host Ltd

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
1,947
First Reported
4 May 2026
Last Reported
5 Aug 2026, 03:24

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS215925
Vpsvault.host Ltd
US US

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

119
Total IPs Monitored
27,203
Total Reports
228.6
Reports per IP

Network Context

This IP address belongs to Vpsvault.host Ltd (AS215925), which manages 119 IP addresses in our monitoring system. Out of these, 27,203 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

85 %

Global Threat Ranking

This IP is more threatening than 85% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 312,015 reported IPs worldwide

Threat Level 8/10 avg: 6.0 +
Total Reports 1,947 avg: 18 ++

Network Comparison

Compared against 209 IPs in ASN 215925

Threat Level 8/10 network avg: 8.5 =
Total Reports 1,947 network avg: 191 ++
Network Vpsvault.host Ltd has overall threat level 3/10

Geographic Comparison

Compared against 65,774 IPs in US

Threat Level 8/10 country avg: 6.5 +
Total Reports 1,947 country avg: 31 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

292,628 threat incidents tracked globally • Last 24h: 17,591 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    65,774 22.5%
  2. 02
    IN
    India IN
    49,096 16.8%
  3. 03
    CN
    China CN
    35,621 12.2%
  4. 04
    BR
    Brazil BR
    15,554 5.3%
  5. 05
    DE
    Germany DE
    10,499 3.6%
  6. 06
    PK
    Pakistan PK
    8,474 2.9%
  7. 07
    ID
    Indonesia ID
    8,403 2.9%
  8. 08
    SG
    Singapore SG
    8,312 2.8%
  9. 09
    RU
    Russia RU
    6,393 2.2%
  10. 10
    NL
    Netherlands NL
    6,295 2.2%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.6/10 Avg Threat
97% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
9.8/10 Avg Threat
94% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "45.198.224.5",
    "threat_level": 8,
    "confidence_score": 94,
    "total_reports": 1947,
    "country_code": "US",
    "isp_name": "Vpsvault.host Ltd",
    "asn": "215925",
    "first_reported": "2026-05-04 05:14:12",
    "last_reported": "2026-08-05 03:24:19",
    "exported_at": "2026-08-06T15:08:19+02:00",
    "source": "https://reportedip.com/ip/45.198.224.5/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.