IP Address

202.189.224.58

IPv4 Public
IN IN
AS17762
Tata Teleservices Maharashtra Ltd
239 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
59% Confidence
239 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
IN
IN Location
Tata Teleservices Maharas... ASN 17762
239 Reports
Honeypot Data Source

Critical Threat

IP 202.189.224.58 is a critical-risk address originating from India that has been classified as an exploited host in 20 distinct honeypot detections, indicating this machine has been compromised and is actively being weaponised by threat actors without its owner's knowledge. With 239 total abuse reports logged between August 2025 and March 2026, this IP presents a severe and persistent threat to any exposed network infrastructure.

The detection data stems exclusively from 20 automated honeypot sensors, which captured evidence of malware and exploit activity including Suricata alerts flagging potentially unsafe SMBv1 protocol usage. The IP is registered to Tata Teleservices Maharashtra Ltd operating on ASN AS17762 within Indian address space. Despite the high volume of historical reports, the activity frequency metric reads at zero out of ten, suggesting the most aggressive attack campaigns may have subsided or shifted to alternative infrastructure. The classification confidence of 59 percent indicates some uncertainty in attribution, though the concentration of exploited host reports strongly supports the conclusion that this address is compromised rather than operator-controlled.

An exploited host classification is particularly dangerous because the machine functions as a unwitting proxy for malicious activity, meaning the origin operator has no awareness of or control over the attacks emanating from their infrastructure. SMBv1 protocol activity is especially concerning given its well-documented vulnerabilities to remote code execution, historically exploited in large-scale ransomware and worm campaigns. The dual presence of malware activity and hacking indicators suggests the compromised system may be running multiple malicious payloads simultaneously, potentially forming part of a botnet or being used for lateral movement operations against additional targets.

Site operators should immediately block IP 202.189.224.58 at the network perimeter and configure intrusion detection systems to alert on any inbound connections from this address. Systems running SMBv1 should be audited and the protocol disabled where feasible, as it is a known attack vector. Deploying tools such as fail2ban or equivalent rate-limiting mechanisms can reduce the impact of any residual scanning activity. Operators who identify this IP in their logs should treat it as a confirmed compromise indicator and conduct internal host forensic analysis to rule out secondary infections.

More threatening than 89% of monitored IPs

Threat Categories

Exploited Host 30
Hacking 1

Technical Details

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Recommended Mitigations

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Reputable Network

This IP is hosted on a network (ASN 17762) with generally good reputation. The ISP Tata Teleservices Maharashtra Ltd maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 59% High Confidence

Confidence History

30. Aug 2025 - 13. Mar 2026
59% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Exploited Host Hacking Honeypot x2 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technical Details

Basic Information

IP Address
202.189.224.58
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
IN IN
ASN
AS17762
ISP
Tata Teleservices Maharashtra Ltd

DNS Information

Reverse DNS
static-58.224.189.202-tataidc.co.in
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
239
First Reported
30 Aug 2025
Last Reported
13 Mar 2026, 08:40

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS17762
Tata Teleservices Maharashtra Ltd
IN IN

Network Threat Assessment

1/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

42
Total IPs Monitored
754
Total Reports
18
Reports per IP

Network Context

This IP address belongs to Tata Teleservices Maharashtra Ltd (AS17762), which manages 42 IP addresses in our monitoring system. Out of these, 754 have been reported for suspicious activities, resulting in a network-wide threat level of 1/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

89 %

Global Threat Ranking

This IP is more threatening than 89% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,981 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 239 avg: 23 ++

Network Comparison

Compared against 60 IPs in ASN 17762

Threat Level 10/10 network avg: 5.2 ++
Total Reports 239 network avg: 14 ++
Network Tata Teleservices Maharashtra Ltd has overall threat level 1/10

Geographic Comparison

Compared against 29,262 IPs in IN

Threat Level 10/10 country avg: 5.4 ++
Total Reports 239 country avg: 5 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,611 threat incidents tracked globally • Last 24h: 18,879 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,485 20.5%
  2. 02
    IN
    India IN THIS IP
    29,222 15.6%
  3. 03
    CN
    China CN
    26,039 13.9%
  4. 04
    BR
    Brazil BR
    10,262 5.5%
  5. 05
    DE
    Germany DE
    7,147 3.8%
  6. 06
    SG
    Singapore SG
    6,479 3.5%
  7. 07
    ID
    Indonesia ID
    5,559 3%
  8. 08
    RU
    Russia RU
    4,710 2.5%
  9. 09
    PK
    Pakistan PK
    4,702 2.5%
  10. 10
    NL
    Netherlands NL
    4,362 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.3/10 Avg Threat
67% Avg Confidence
18 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "202.189.224.58",
    "threat_level": 10,
    "confidence_score": 59,
    "total_reports": 239,
    "country_code": "IN",
    "isp_name": "Tata Teleservices Maharashtra Ltd",
    "asn": "17762",
    "first_reported": "2025-08-30 07:31:07",
    "last_reported": "2026-03-13 08:40:35",
    "exported_at": "2026-06-09T13:10:34+02:00",
    "source": "https://reportedip.de/ip/202.189.224.58/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.