IP Address

95.215.0.144

IPv4 Public
RU RU
AS34665
Petersburg Internet Network ltd.
832 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
8/10 Threat
78% Confidence
832 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
RU
RU Location
Petersburg Internet Netwo... ASN 34665
832 Reports
Honeypot Data Source

Substantial Risk

IP address 95.215.0.144 is a high-risk address with a threat level of 8 out of 10 that has generated 814 abuse reports from automated honeypot sensors since August 2025, with the most recent activity logged in June 2026. This Russian-origin IP, operating through ASN AS34665 under the control of Petersburg Internet Network ltd., demonstrates an activity frequency rated 8 out of 10, indicating sustained and persistent hostile operations against target systems worldwide.

The volume and consistency of reports paint a concerning picture. With 814 total reports sourced from 20 distinct automated honeypot sensors, the detection confidence stands at 78%, reflecting reliable identification of malicious behavior patterns. The reported threat categories split between Hacking activity (17 recent reports) and Exploited Host behavior (7 recent reports), suggesting this infrastructure may simultaneously serve as an attack platform while potentially being leveraged from compromised upstream systems. Network detection systems recorded multiple Suricata alerts including broken packet acknowledgments, bidirectional protocol mismatches, and unexpected protocol detections, alongside direct evidence of Redis attack patterns and SSH sessions established on non-standard ports.

The predominant Hacking classification encompasses intrusion attempts, vulnerability exploitation, and unauthorized access vectors. The specific attack patterns observed, particularly Redis exploitation attempts and anomalous SSH session establishment, represent concrete entry-point strategies used to compromise web-facing services and authentication systems. The Exploited Host indicators suggest this IP may itself be operating from a previously compromised system, meaning the true origin operators could be obscured. These combined patterns indicate this address is actively probing and attacking infrastructure at scale, with the goal of establishing persistent unauthorized access or deploying additional attack payloads.

Network defenders should treat IP 95.215.0.144 as a hostile source requiring immediate blocking at the firewall or network perimeter. Implementing fail2ban or similar dynamic deny-listing tools that automatically block repeated malicious connection attempts provides automated protection against the observed attack patterns. All Redis instances should be network-isolated and protected with strong authentication, as the detected Redis attack vectors indicate active targeting of misconfigured deployments. Organizations running SSH services should enforce key-based authentication, disable password authentication entirely, and consider relocating services to non-standard ports to reduce exposure to the SSH probing activity documented in honeypot reports. Regular monitoring of authentication logs for source IPs matching this address or adjacent ranges will help identify any successful compromise attempts.

More threatening than 80% of monitored IPs

Threat Categories

Hacking 22
Exploited Host 11
Web App Attack 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Consistent Activity

Steady malicious activity over 4 weeks indicates persistent threat actor operations.

First Observed 11. May 2026
Last Activity 9. June 2026
Recent (7 days) 16 incidents

Reputable Network

This IP is hosted on a network (ASN 34665) with generally good reputation. The ISP Petersburg Internet Network ltd. maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Long-term blocking recommended.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 8/10 High
Confidence Score 78% Verified

Confidence History

27. May 2026 - 9. Jun 2026
78% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
New Exploited Host Honeypot 75%
New Exploited Host Hacking Honeypot x2 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Web App Attack Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Hacking Honeypot 75%
Exploited Host Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Exploited Host Hacking Honeypot x2 75%

Technical Details

Basic Information

IP Address
95.215.0.144
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
RU RU
ASN
AS34665
ISP
Petersburg Internet Network ltd.

DNS Information

Reverse DNS
scan.f6.security
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
832
First Reported
15 Aug 2025
Last Reported
9 Jun 2026, 02:54

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS34665
Petersburg Internet Network ltd.
RU RU

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

7
Total IPs Monitored
951
Total Reports
135.9
Reports per IP

Network Context

This IP address belongs to Petersburg Internet Network ltd. (AS34665), which manages 7 IP addresses in our monitoring system. Out of these, 951 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

80 %

Global Threat Ranking

This IP is more threatening than 80% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,338 reported IPs worldwide

Threat Level 8/10 avg: 5.3 ++
Total Reports 832 avg: 23 ++

Network Comparison

Compared against 8 IPs in ASN 34665

Threat Level 8/10 network avg: 8.1 =
Total Reports 832 network avg: 145 ++
Network Petersburg Internet Network ltd. has overall threat level 3/10

Geographic Comparison

Compared against 4,701 IPs in RU

Threat Level 8/10 country avg: 5.3 ++
Total Reports 832 country avg: 17 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU THIS IP
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "95.215.0.144",
    "threat_level": 8,
    "confidence_score": 78,
    "total_reports": 832,
    "country_code": "RU",
    "isp_name": "Petersburg Internet Network ltd.",
    "asn": "34665",
    "first_reported": "2025-08-15 03:26:53",
    "last_reported": "2026-06-09 02:54:26",
    "exported_at": "2026-06-09T07:59:35+02:00",
    "source": "https://reportedip.de/ip/95.215.0.144/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.