IP Address

193.142.147.209

IPv4 Public
DE DE
AS213438
ColocaTel Inc.
11,438 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
61% Confidence
11,438 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
DE
DE Location
ColocaTel Inc. ASN 213438
11,438 Reports
Mixed Data Source

Severe Risk

IP address 193.142.147.209 is a critical-risk address operating from ColocaTel Inc. network infrastructure in Germany, with 11,438 abuse reports logged against it across approximately five months of active detection. This IP presents a maximum threat level of 10/10 and is primarily associated with automated web application attacks targeting WordPress environments, alongside broader hacking activity and unauthorized access attempts. The volume and consistency of reports indicate sustained, malicious traffic rather than isolated probing.

Detection data sourced from automated honeypot sensors and community submissions documents a persistent threat actor generating over eleven thousand reports between October 2025 and February 2026. The overwhelming majority of confirmed incidents involve web application reconnaissance and exploitation attempts, with specific emphasis on WordPress infrastructure: unauthorized cron execution, suspicious backup-related POST requests, and configuration exposure probes. The remaining reported categories include general hacking activity, DDoS attack signatures, and brute-force style intrusion attempts. The geographic origin in Germany and operator association with ColocaTel Inc. provides network context, though threat actors routinely leverage compromised or anonymized hosting to obscure true attribution.

Web application attacks against WordPress installations represent a significant real-world risk, as automated tools routinely scan the internet for vulnerable deployments. The WP Cron Abuse and WP Config Exposure patterns observed in detection data suggest attackers are attempting to schedule unauthorized tasks and extract sensitive configuration information to facilitate further compromise. These techniques are frequently employed in automated exploitation kits designed to compromise websites at scale, potentially leading to data theft, site defacement, or pivot into broader network infrastructure.

Site operators should immediately block or rate-limit this address at the firewall level and monitor closely for any similar scanning patterns from adjacent IP ranges. Deploying a web application firewall with rulesets covering OWASP Top 10 vulnerabilities will mitigate many of the observed attack vectors. WordPress hardening measures—including restricting wp-cron execution, securing configuration files outside webroot, and disabling directory indexing—substantially reduce exposure. Implementing fail2ban or equivalent intrusion prevention tools can automatically block repeated offending connections, while maintaining comprehensive access logging enables rapid investigation of any attempted exploitation.

More threatening than 90% of monitored IPs

Threat Categories

Hacking 22
Web App Attack 8
WP Config Exposure 7
DDoS Attack 6
WP Cron Abuse 6

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 213438) with generally good reputation. The ISP ColocaTel Inc. maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 61% High Confidence

Confidence History

9. Feb 2026 - 10. Feb 2026
61% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Web App Attack Honeypot 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%
Hacking Honeypot 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
WP Config Exposure Hacking Community 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
Hacking Honeypot x2 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
WP Config Exposure Hacking WP Cron Abuse +1 Community x2 75%

Technical Details

Basic Information

IP Address
193.142.147.209
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
DE DE
ASN
AS213438
ISP
ColocaTel Inc.

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
11,438
First Reported
23 Oct 2025
Last Reported
10 Feb 2026, 10:22

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS213438
ColocaTel Inc.
BG BG

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

61
Total IPs Monitored
15,820
Total Reports
259.3
Reports per IP

Network Context

This IP address belongs to ColocaTel Inc. (AS213438), which manages 61 IP addresses in our monitoring system. Out of these, 15,820 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

90 %

Global Threat Ranking

This IP is more threatening than 90% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,471 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 11,438 avg: 23 ++

Network Comparison

Compared against 80 IPs in ASN 213438

Threat Level 10/10 network avg: 6.3 ++
Total Reports 11,438 network avg: 225 ++
Network ColocaTel Inc. has overall threat level 3/10

Geographic Comparison

Compared against 7,142 IPs in DE

Threat Level 10/10 country avg: 5.8 ++
Total Reports 11,438 country avg: 61 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,140 threat incidents tracked globally • Last 24h: 19,043 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,446 20.5%
  2. 02
    IN
    India IN
    29,023 15.5%
  3. 03
    CN
    China CN
    26,021 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE THIS IP
    7,142 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,539 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,654 2.5%
  10. 10
    NL
    Netherlands NL
    4,356 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.6/10 Avg Threat
91% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

2 Related IPs
4/10 Avg Threat
60% Avg Confidence
1 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "193.142.147.209",
    "threat_level": 10,
    "confidence_score": 61,
    "total_reports": 11438,
    "country_code": "DE",
    "isp_name": "ColocaTel Inc.",
    "asn": "213438",
    "first_reported": "2025-10-23 21:29:29",
    "last_reported": "2026-02-10 10:22:14",
    "exported_at": "2026-06-09T08:53:04+02:00",
    "source": "https://reportedip.de/ip/193.142.147.209/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.