IP Address

212.72.14.244

IPv4 Public
OM OM
AS28885
Oman Telecommunications Company (S.A.O.G)
1,270 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
63% Confidence
1,270 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
OM
OM Location
Oman Telecommunications C... ASN 28885
1,270 Reports
Honeypot Data Source

Critical Alert

IP 212.72.14.244 is a maximum-threat-level address associated with 1,270 incident reports that indicate it is functioning both as an exploited compromise and an active attack platform conducting SSH brute-force operations against remote services. Originating from Oman and operating within the Oman Telecommunications Company (S.A.O.G) network (ASN AS28885), this IP has been flagged across 20 automated honeypot sensors between January and April 2026, with recent activity concentrated in SSH-related intrusion categories.

The report volume of 1,270 incidents across a four-month window underscores sustained malicious intent, while the activity frequency rating of zero suggests burst-pattern behaviour rather than constant bombardment. Among the most recent reports, Hacking activity accounts for 13 incidents, SSH brute-force attempts comprise 12, and three separate Exploited Host designations confirm the system itself has been compromised and is being leveraged without the operator's knowledge. The detection footprint spans multiple automated honeypot sensors, indicating the IP has been observed attacking diverse infrastructure rather than a single target.

The combination of SSH brute-force activity with confirmed Exploited Host status is particularly concerning. This IP appears to be running an SSH service that has itself been compromised, turning the host into an automated attack platform capable of launching credential-guessing campaigns against external servers. Attack-pattern analysis shows repeated SSH session initiations and brute-force attempts, consistent with automated tools designed to compromise SSH daemons through dictionary-based password attacks or the exploitation of vulnerable SSH configurations. For any organization running exposed SSH services, this IP represents both a direct attack vector and evidence of a compromised system being weaponized at scale.

Site operators should immediately block IP 212.72.14.244 at the firewall or network perimeter, and consider implementing key-based authentication for SSH access while disabling root login to eliminate the primary credential-guessing target. Deploying automated dynamic blocking tools such as fail2ban can detect and quarantine repeated authentication failures in real time. Changing the default SSH listening port reduces the surface area for automated scanning campaigns. Organizations with SSH services exposed to the internet should also audit access logs for any authentication attempts originating from this address and review authentication failure thresholds as part of a broader hardening strategy.

More threatening than 91% of monitored IPs

Threat Categories

SSH 21
Hacking 17
Exploited Host 4

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 28885) with generally good reputation. The ISP Oman Telecommunications Company (S.A.O.G) maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 60% High Confidence

Confidence History

21. Jan 2026 - 30. Apr 2026
63% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Exploited Host Honeypot x2 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Honeypot 75%
Hacking Honeypot 75%
SSH Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
SSH Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
212.72.14.244
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
OM OM
ASN
AS28885
ISP
Oman Telecommunications Company (S.A.O.G)

DNS Information

Reverse DNS
i244.tb-as-18.omantel.net.om
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
1,270
First Reported
21 Jan 2026
Last Reported
16 Apr 2026, 06:05

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS28885
Oman Telecommunications Company (S.A.O.G)
OM OM

Network Threat Assessment

1/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

17
Total IPs Monitored
1,440
Total Reports
84.7
Reports per IP

Network Context

This IP address belongs to Oman Telecommunications Company (S.A.O.G) (AS28885), which manages 17 IP addresses in our monitoring system. Out of these, 1,440 have been reported for suspicious activities, resulting in a network-wide threat level of 1/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

91 %

Global Threat Ranking

This IP is more threatening than 91% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 208,746 reported IPs worldwide

Threat Level 10/10 avg: 5.4 ++
Total Reports 1,270 avg: 22 ++

Network Comparison

Compared against 393 IPs in ASN 28885

Threat Level 10/10 network avg: 5.6 ++
Total Reports 1,270 network avg: 5 ++
Network Oman Telecommunications Company (S.A.O.G) has overall threat level 1/10

Geographic Comparison

Compared against 568 IPs in OM

Threat Level 10/10 country avg: 5.6 ++
Total Reports 1,270 country avg: 4 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

195,803 threat incidents tracked globally • Last 24h: 17,180 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    40,002 20.4%
  2. 02
    IN
    India IN
    31,242 16%
  3. 03
    CN
    China CN
    26,684 13.6%
  4. 04
    BR
    Brazil BR
    10,638 5.4%
  5. 05
    DE
    Germany DE
    7,411 3.8%
  6. 06
    SG
    Singapore SG
    6,670 3.4%
  7. 07
    ID
    Indonesia ID
    5,826 3%
  8. 08
    PK
    Pakistan PK
    5,061 2.6%
  9. 09
    RU
    Russia RU
    4,999 2.6%
  10. 10
    NL
    Netherlands NL
    4,545 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
8.2/10 Avg Threat
62% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

1 Related IPs
8/10 Avg Threat
72% Avg Confidence
1 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "212.72.14.244",
    "threat_level": 10,
    "confidence_score": 63,
    "total_reports": 1270,
    "country_code": "OM",
    "isp_name": "Oman Telecommunications Company (S.A.O.G)",
    "asn": "28885",
    "first_reported": "2026-01-21 01:29:00",
    "last_reported": "2026-04-16 06:05:04",
    "exported_at": "2026-06-13T16:00:46+02:00",
    "source": "https://reportedip.de/ip/212.72.14.244/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.