IP Address

50.212.116.145

IPv4 Public
US US
AS7922
Comcast Cable Communications, LLC
1,598 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
79% Confidence
1,598 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
US
US Location
Comcast Cable Communicati... ASN 7922
1,598 Reports
Honeypot Data Source

Critical Threat

IP 50.212.116.145 is a high-risk address associated with SSH brute-force attacks, generating 1,598 reports from automated honeypot sensors across a two-month window in early 2026. Assigned to Comcast Cable Communications under ASN AS7922 in the United States, this residential IP has been flagged with a maximum threat score of 10 out of 10, reflecting a sustained and aggressive campaign targeting Secure Shell services.

Analysis of the reported threat categories shows an even split between general hacking attempts and SSH-specific activity, with 19 reports attributed to each classification. Suricata sensor alerts explicitly document recurring SSH brute-force attempts and established sessions on expected SSH ports, confirming systematic credential-guessing behaviour. The detection footprint spans 20 independent honeypot sources, indicating broad probing across multiple infrastructure points. Although current activity frequency is assessed at zero out of ten, the sheer volume of historical reports demonstrates a persistent automated threat that operators should not dismiss.

SSH brute-force activity represents a direct path to server compromise. Attackers systematically iterate through username and password combinations to gain unauthorized shell access; a single successful guess can yield full administrative control over a target host. Compromised servers frequently become platforms for data exfiltration, lateral network movement, cryptocurrency mining or botnet recruitment. The volume of 1,598 reports from this single IP reflects an automated, high-frequency operation rather than casual scanning, meaning any exposed SSH service within range faced repeated, targeted attempts during the reporting window.

Operators maintaining publicly accessible SSH services should implement key-based authentication exclusively, eliminating password-based logins that are vulnerable to guessing. Moving the SSH daemon to a non-standard port reduces exposure to automated scanners that target port 22 by default. Deploying fail2ban or equivalent intrusion-prevention tools to dynamically block IPs after repeated failed attempts provides an automated defensive layer. Disabling root login, enforcing strong passphrase policies, and implementing connection rate-limiting at the network perimeter further harden exposure. Continuous monitoring of authentication logs for unusual patterns remains essential for early detection of any successful intrusion despite these precautions.

More threatening than 94% of monitored IPs

Threat Categories

Hacking 29
SSH 29

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Moderate Network Risk

The network hosting this IP (ASN 7922, operated by Comcast Cable Communications, LLC) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 72% High Confidence

Confidence History

15. Apr 2026
79% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%

Technical Details

Basic Information

IP Address
50.212.116.145
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS7922
ISP
Comcast Cable Communications, LLC

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
1,598
First Reported
27 Mar 2026
Last Reported
15 Apr 2026, 22:10

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS7922
Comcast Cable Communications, LLC
US US

Network Threat Assessment

4/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

374
Total IPs Monitored
3,426
Total Reports
9.2
Reports per IP

Network Context

This IP address belongs to Comcast Cable Communications, LLC (AS7922), which manages 374 IP addresses in our monitoring system. Out of these, 3,426 have been reported for suspicious activities, resulting in a network-wide threat level of 4/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

94 %

Global Threat Ranking

This IP is more threatening than 94% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,341 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 1,598 avg: 23 ++

Network Comparison

Compared against 515 IPs in ASN 7922

Threat Level 10/10 network avg: 4.8 ++
Total Reports 1,598 network avg: 7 ++
Network Comcast Cable Communications, LLC has overall threat level 4/10

Geographic Comparison

Compared against 38,426 IPs in US

Threat Level 10/10 country avg: 5.9 ++
Total Reports 1,598 country avg: 41 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.2/10 Avg Threat
94% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "50.212.116.145",
    "threat_level": 10,
    "confidence_score": 79,
    "total_reports": 1598,
    "country_code": "US",
    "isp_name": "Comcast Cable Communications, LLC",
    "asn": "7922",
    "first_reported": "2026-03-27 12:25:54",
    "last_reported": "2026-04-15 22:10:25",
    "exported_at": "2026-06-09T08:00:56+02:00",
    "source": "https://reportedip.de/ip/50.212.116.145/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.