IP Address

45.134.26.79

IPv4 Public
RU RU
AS198953
Proton66 OOO
170 Reports
This IP is under Observation Suspicious activity detected - monitor closely
8/10 Threat
65% Confidence
170 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
RU
RU Location
Proton66 OOO ASN 198953
170 Reports
Honeypot Data Source

Significant Threat

IP 45.134.26.79 is a high-risk address linked to SSH brute-force attacks, assessed with a threat level of 8/10 based on 170 total abuse reports detected by automated honeypot infrastructure between August and October 2025.

Community and sensor reporting indicates this Russian-origin IP address has generated a substantial volume of abuse reports, with the network operated by Proton66 OOO under ASN AS198953. All 170 reports across the three-month observation window cite SSH as the targeted service, with 20 recent reports recorded from honeypot sensors. The detection originates entirely from honeypot infrastructure rather than direct victim reports, suggesting the activity represents opportunistic scanning rather than confirmed successful intrusions against production systems. The temporal distribution of reports spans August through October 2025, establishing a sustained presence rather than a transient probe.

SSH brute-force attacks attempt to gain unauthorized server access through systematic password guessing or exploitation of SSH service vulnerabilities. The attack pattern detected (fail2ban sshd) confirms automated credential-guessing behaviour consistent with bot-driven scanning campaigns. While the 65% confidence score reflects uncertainty regarding the ultimate intent, the volume of reports indicates persistent automated scanning that poses a concrete risk to any internet-exposed SSH service with weak or default credentials. Attackers leverage such infrastructure to compromise servers, deploy malware or establish persistent backdoor access.

Site operators running accessible SSH services should immediately audit authentication configurations. Deploying key-based authentication eliminates password-guessing risk entirely. Changing the default SSH port reduces automated scanning exposure. Implementing defensive tools such as fail2ban to automatically block repeated authentication failures mitigates brute-force attempts. Disabling root login and enforcing strong, complex passwords for any remaining password-based accounts further hardens exposure. Regular monitoring of authentication logs for unusual source IPs or patterns provides early warning of sustained probing campaigns.

More threatening than 79% of monitored IPs

Threat Categories

SSH 30

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 198953) with generally good reputation. The ISP Proton66 OOO maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 0/10 Inactive
Confidence Score 58% High Confidence

Confidence History

27. Oct 2025
65% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
45.134.26.79
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
RU RU
ASN
AS198953
ISP
Proton66 OOO

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
170
First Reported
21 Aug 2025
Last Reported
27 Oct 2025, 10:44

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS198953
Proton66 OOO
RU RU

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

29
Total IPs Monitored
9,673
Total Reports
333.6
Reports per IP

Network Context

This IP address belongs to Proton66 OOO (AS198953), which manages 29 IP addresses in our monitoring system. Out of these, 9,673 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

79 %

Global Threat Ranking

This IP is more threatening than 79% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,560 reported IPs worldwide

Threat Level 8/10 avg: 5.3 ++
Total Reports 170 avg: 23 ++

Network Comparison

Compared against 35 IPs in ASN 198953

Threat Level 8/10 network avg: 8.3 =
Total Reports 170 network avg: 264 -
Network Proton66 OOO has overall threat level 3/10

Geographic Comparison

Compared against 4,703 IPs in RU

Threat Level 8/10 country avg: 5.3 ++
Total Reports 170 country avg: 17 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,269 threat incidents tracked globally • Last 24h: 19,041 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,456 20.5%
  2. 02
    IN
    India IN
    29,090 15.5%
  3. 03
    CN
    China CN
    26,026 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,143 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,543 3%
  8. 08
    RU
    Russia RU THIS IP
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,670 2.5%
  10. 10
    NL
    Netherlands NL
    4,357 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.6/10 Avg Threat
82% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

1 Related IPs
8/10 Avg Threat
72% Avg Confidence
1 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "45.134.26.79",
    "threat_level": 8,
    "confidence_score": 65,
    "total_reports": 170,
    "country_code": "RU",
    "isp_name": "Proton66 OOO",
    "asn": "198953",
    "first_reported": "2025-08-21 09:40:01",
    "last_reported": "2025-10-27 10:44:38",
    "exported_at": "2026-06-09T09:44:02+02:00",
    "source": "https://reportedip.de/ip/45.134.26.79/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.