IP Address

176.120.22.47

IPv4 Public
RU RU
AS198953
Proton66 OOO
881 Reports
This IP is under Observation Suspicious activity detected - monitor closely
8/10 Threat
66% Confidence
881 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Above Average Risk
RU
RU Location
Proton66 OOO ASN 198953
881 Reports
Honeypot Data Source

Notable Threat

IP 176.120.22.47, registered in Russia and operated by Proton66 OOO (AS198953), is a high-risk address with an 8/10 threat level that has accumulated 881 abuse reports from 20 automated honeypot sensors over a three-month period ending in March 2026, with SSH brute-force activity dominating the threat landscape.

The detection data reveals a pattern consistent with an established, persistent threat actor: 881 total reports across a relatively short 90-day window, with 19 of the most recent reports specifically categorised as SSH attacks alongside Hacking and Brute-Force variants. The activity frequency score of 0/10 indicates that the IP does not maintain constant connectivity but rather engages in irregular, burst-style campaigns — a characteristic often associated with actors cycling through large volumes of sources to evade rate-based defences. The fail2ban pattern data confirms this is not a first-time offender; multiple recidive violations (five per instance) across both sshd and recidive jail chains indicate this address has been blocked, returned, and blocked again, earning it a multi-jail offender designation. Despite a confidence score of 66%, the sheer volume and consistency of reporting from 20 independent sensor sources establish a credible threat profile.

SSH brute-force attacks represent one of the most common initial-access vectors in internet-facing infrastructure. An attacker systematically guessing authentication credentials against an exposed SSH daemon can achieve domain administrator or root-level compromise within hours if weak or default passwords remain in use. Once access is obtained, threat actors typically deploy persistence mechanisms, cryptocurrency miners or pivot laterally to adjacent systems within the same network segment. The recidive classification observed in the pattern data suggests this particular IP has been blocked previously yet continues to target new honeypot sensors — indicating either automated tooling that ignores blocklists or a deliberate strategy of rotating through compromised infrastructure to resume attacks.

Site operators running publicly accessible SSH services should treat IP 176.120.22.47 as a confirmed malicious source and block it at the network perimeter immediately. Implement fail2ban or equivalent rate-limiting tools to automatically ban IPs after a threshold of failed authentication attempts, and enforce key-based authentication exclusively while disabling password-based login and root access via SSH configuration. Exposing SSH on non-standard ports offers marginal obfuscation but should supplement, not replace, strong credential and access-control policies. Continuous monitoring of authentication logs and deployment of intrusion-detection systems will further reduce the window of opportunity for automated intrusion attempts from addresses like this one.

More threatening than 79% of monitored IPs

Threat Categories

SSH 29
Hacking 3
Brute-Force 3

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 198953) with generally good reputation. The ISP Proton66 OOO maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 8/10 High
Critical
Activity Frequency 0/10 Inactive
Confidence Score 62% High Confidence

Confidence History

1. Mar 2026 - 3. Mar 2026
66% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Brute-Force Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
176.120.22.47
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
RU RU
ASN
AS198953
ISP
Proton66 OOO

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
881
First Reported
21 Jan 2026
Last Reported
3 Mar 2026, 08:28

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS198953
Proton66 OOO
RU RU

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

29
Total IPs Monitored
9,673
Total Reports
333.6
Reports per IP

Network Context

This IP address belongs to Proton66 OOO (AS198953), which manages 29 IP addresses in our monitoring system. Out of these, 9,673 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

79 %

Global Threat Ranking

This IP is more threatening than 79% of all IPs in our database.

High Threat Percentile

Global Comparison

Compared against 199,384 reported IPs worldwide

Threat Level 8/10 avg: 5.3 ++
Total Reports 881 avg: 23 ++

Network Comparison

Compared against 35 IPs in ASN 198953

Threat Level 8/10 network avg: 8.3 =
Total Reports 881 network avg: 264 ++
Network Proton66 OOO has overall threat level 3/10

Geographic Comparison

Compared against 4,703 IPs in RU

Threat Level 8/10 country avg: 5.3 ++
Total Reports 881 country avg: 17 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU THIS IP
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.6/10 Avg Threat
82% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "176.120.22.47",
    "threat_level": 8,
    "confidence_score": 66,
    "total_reports": 881,
    "country_code": "RU",
    "isp_name": "Proton66 OOO",
    "asn": "198953",
    "first_reported": "2026-01-21 08:56:31",
    "last_reported": "2026-03-03 08:28:08",
    "exported_at": "2026-06-09T08:16:29+02:00",
    "source": "https://reportedip.de/ip/176.120.22.47/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.