IP Address

77.83.39.156

IPv4 Public
UA UA
AS214940
Kprohost LLC
718 Reports
This IP is under Observation Suspicious activity detected - monitor closely
7/10 Threat
68% Confidence
718 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Moderate Risk
UA
UA Location
Kprohost LLC ASN 214940
718 Reports
Honeypot Data Source

Significant Threat

IP 77.83.39.156, registered in Ukraine and operated by Kprohost LLC, is a high-risk address with a threat level of 7/10, associated with 718 total abuse reports predominantly documenting email spam and hacking activity. The IP was first flagged in January 2026 and most recently in March 2026, with detection sourced from 20 automated honeypot sensors across the community. Despite the significant report volume, the activity frequency score of 0/10 suggests these incidents are dispersed rather than continuous, indicating opportunistic or scheduled scanning behavior rather than sustained automated attacks.

Analysis of the reported threat categories reveals Email Spam as the dominant activity with 20 recent reports, followed by Hacking with 17 reports. Network-based detection via Suricata sensors flagged SMTP abuse patterns, specifically malformed packets with broken acknowledgements commonly associated with spam relay attempts and bulk email distribution. The combination of honeypot detections and the specific protocol violations observed indicates this IP is actively engaged in unsolicited email operations, potentially for advertising, phishing campaigns, or malware distribution. The low activity frequency relative to total reports suggests this host may rotate through targets or operate intermittently to evade detection thresholds.

SMTP spam represents a concrete operational risk for exposed mail servers, as compromised or abused mail relays can damage an organization's sender reputation, trigger blocklisting, and serve as a vector for phishing or malicious payload delivery. The hacking activity reported alongside the spam suggests this IP may also be probing for vulnerable mail transfer agents or attempting to exploit configuration weaknesses in exposed SMTP services.

Site operators should implement immediate blocking or rate-limiting for inbound connections from this address, particularly on TCP port 25. Deploying or strengthening fail2ban rules tailored to SMTP abuse patterns and malformed packet signatures can automate this response. Implementing strict SPF, DKIM, and DMARC email authentication protocols will reduce the impact of any spam originating through or relayed via this IP. Continuous monitoring of mail logs for connections from this address and regular review of honeypot telemetry will help assess whether the threat posture changes over time.

More threatening than 74% of monitored IPs

Threat Categories

Email Spam 30
Hacking 26

Technical Details

Email spam involves mass distribution of unwanted emails, often for advertising, phishing, or malware delivery.

Recommended Mitigations

Implement SPF, DKIM, DMARC, and use reputable email filtering services.

Reputable Network

This IP is hosted on a network (ASN 214940) with generally good reputation. The ISP Kprohost LLC maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 7/10 High
High
Activity Frequency 0/10 Inactive
Confidence Score 63% High Confidence

Confidence History

18. Mar 2026 - 19. Mar 2026
68% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Email Spam Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Honeypot 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Honeypot 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Hacking Email Spam Honeypot x2 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Honeypot 75%
Hacking Email Spam Honeypot x2 75%
Email Spam Honeypot 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%
Email Spam Hacking Honeypot x2 75%

Technical Details

Basic Information

IP Address
77.83.39.156
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
UA UA
ASN
AS214940
ISP
Kprohost LLC

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
718
First Reported
26 Jan 2026
Last Reported
19 Mar 2026, 10:59

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS214940
Kprohost LLC
UA UA

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

85
Total IPs Monitored
21,766
Total Reports
256.1
Reports per IP

Network Context

This IP address belongs to Kprohost LLC (AS214940), which manages 85 IP addresses in our monitoring system. Out of these, 21,766 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

74 %

Global Threat Ranking

This IP is more threatening than 74% of all IPs in our database.

Above Average Threat

Global Comparison

Compared against 199,347 reported IPs worldwide

Threat Level 7/10 avg: 5.3 +
Total Reports 718 avg: 23 ++

Network Comparison

Compared against 105 IPs in ASN 214940

Threat Level 7/10 network avg: 6.8 =
Total Reports 718 network avg: 235 ++
Network Kprohost LLC has overall threat level 3/10

Geographic Comparison

Compared against 681 IPs in UA

Threat Level 7/10 country avg: 5.6 +
Total Reports 718 country avg: 145 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.7/10 Avg Threat
94% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
9.5/10 Avg Threat
94% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "77.83.39.156",
    "threat_level": 7,
    "confidence_score": 68,
    "total_reports": 718,
    "country_code": "UA",
    "isp_name": "Kprohost LLC",
    "asn": "214940",
    "first_reported": "2026-01-26 08:34:11",
    "last_reported": "2026-03-19 10:59:56",
    "exported_at": "2026-06-09T08:00:59+02:00",
    "source": "https://reportedip.de/ip/77.83.39.156/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.