IP Address

176.120.22.13

IPv4 Public
RU RU
Proton66 OOO
679 Reports
This IP is under Observation Suspicious activity detected - monitor closely
8/10 Threat
63% Confidence
679 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
RU
RU Location
Proton66 OOO ISP
679 Reports
Honeypot Data Source

Elevated Risk

IP 176.120.22.13 is a high-risk Russian address associated with repeated SSH brute-force attacks, with automated honeypot sensors recording 679 abuse reports over a two-month window in early 2026.

The IP belongs to Proton66 OOO, a Russian network operator, and was first flagged in January 2026 with continued reporting activity through February 2026. All recent threat reports consistently cite SSH as the attack vector, with honeypot sensors detecting the address on multiple occasions. While the overall report volume is substantial at 679 incidents, the activity frequency metric suggests the most recent detection window shows limited fresh attempts, likely indicating the address has been blocked by defensive systems such as fail2ban on the targeted SSH daemons. The 63% confidence score reflects reasonable certainty that this traffic represents malicious scanning behavior rather than legitimate server access, though the exact timeline of the most recent activity cannot be precisely determined from the available data.

SSH brute-force attacks represent one of the most common pathways attackers use to gain unauthorized access to Linux servers and network infrastructure. Threat actors systematically attempt username and password combinations against exposed SSH services, exploiting weak or default credentials to establish a foothold on targeted systems. Once inside, attackers can deploy malware, exfiltrate data, or use the compromised server as a jumping-off point for further network intrusion. The volume of reports for IP 176.120.22.13 indicates sustained, automated scanning activity rather than opportunistic probing.

Network administrators should immediately block IP 176.120.22.13 at the firewall level and ensure fail2ban or equivalent intrusion prevention tools are actively monitoring SSH authentication logs. Enforcing key-based authentication exclusively, disabling root login, and moving SSH to a non-standard port will significantly reduce exposure to automated scanning. Continuous monitoring of authentication logs and implementing account lockout policies after repeated failed attempts provide additional layers of defense against this threat category.

More threatening than 78% of monitored IPs

Threat Categories

SSH 30

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 0) with generally good reputation. The ISP Proton66 OOO maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 0/10 Inactive
Confidence Score 60% High Confidence

Confidence History

12. Feb 2026 - 13. Feb 2026
63% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
176.120.22.13
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
RU RU
ASN
Unknown
ISP
Proton66 OOO

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
679
First Reported
19 Jan 2026
Last Reported
13 Feb 2026, 18:22

Comparative Analysis

How this IP compares to others in our threat intelligence database

78 %

Global Threat Ranking

This IP is more threatening than 78% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,554 reported IPs worldwide

Threat Level 8/10 avg: 5.3 ++
Total Reports 679 avg: 23 ++

Geographic Comparison

Compared against 4,703 IPs in RU

Threat Level 8/10 country avg: 5.3 ++
Total Reports 679 country avg: 17 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,269 threat incidents tracked globally • Last 24h: 19,041 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,456 20.5%
  2. 02
    IN
    India IN
    29,090 15.5%
  3. 03
    CN
    China CN
    26,026 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,143 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,543 3%
  8. 08
    RU
    Russia RU THIS IP
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,670 2.5%
  10. 10
    NL
    Netherlands NL
    4,357 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "176.120.22.13",
    "threat_level": 8,
    "confidence_score": 63,
    "total_reports": 679,
    "country_code": "RU",
    "isp_name": "Proton66 OOO",
    "asn": "0",
    "first_reported": "2026-01-19 17:21:15",
    "last_reported": "2026-02-13 18:22:05",
    "exported_at": "2026-06-09T09:43:03+02:00",
    "source": "https://reportedip.de/ip/176.120.22.13/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.