IP Address

103.2.225.33

IPv4 Public
VN VN
AS131423
Branch of Long Van System Solution JSC - Hanoi
184 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
69% Confidence
184 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
VN
VN Location
Branch of Long Van System... ASN 131423
184 Reports
Honeypot Data Source

Critical Alert

IP 103.2.225.33 is a critical-risk address operating from Vietnam that has been consistently flagged for SSH brute-force attack activity, with 184 independent abuse reports filed against this single address over a five-month observation window ending in March 2026. Despite a modest activity frequency score of 0/10, the sheer volume of automated honeypot sensor detections and the maximum threat-level rating establish this as one of the more persistently malicious IPs in recent regional telemetry.

Community-driven reporting and automated honeypot sensors recorded 184 total incidents, with the current reported threat category dominated entirely by SSH activity—specifically 20 recent reports all catalogued under SSH. The attack-pattern logs reveal repeated fail2ban trigger events across multiple honeypot instances, with violation counts ranging from 10 to 26 per detection cycle, indicating sustained, multi-wave authentication guessing campaigns. The originating network is AS131423, operated by Branch of Long Van System Solution JSC based in Hanoi, Vietnam. The address was first reported in October 2025 and most recently flagged in March 2026, spanning approximately five months of continuous hostile activity.

SSH brute-force attacks represent one of the most common and effective initial-access vectors in network intrusion campaigns. Attackers systematically automate credential-guessing attempts against exposed SSH daemons, exploiting weak or default passwords to gain unauthorized shell access to servers. Once inside, threat actors can pivot laterally, exfiltrate data, deploy malware or ransomware, and establish persistent backdoors. The repeated fail2ban violation patterns observed from IP 103.2.225.33 demonstrate methodical, sustained scanning behaviour rather than opportunistic probing—suggesting the operator is actively targeting vulnerable SSH endpoints at scale.

Site administrators should treat any inbound connection attempts from this address as hostile and block it at the network perimeter immediately. Implementing key-based authentication exclusively, disabling password-based SSH login entirely, and repositioning the SSH service to a non-standard port materially reduce the attack surface. Deploying or configuring fail2ban with strict ban thresholds will automatically block repeated authentication failures. Continuous monitoring of authentication logs for patterns consistent with brute-force activity and enforcing account lockout policies after a small number of failed attempts provide additional defensive layers against this class of threat.

More threatening than 92% of monitored IPs

Threat Categories

SSH 30

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 131423) with generally good reputation. The ISP Branch of Long Van System Solution JSC - Hanoi maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 67% High Confidence

Confidence History

1. Mar 2026 - 25. Mar 2026
69% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
103.2.225.33
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
VN VN
ASN
AS131423
ISP
Branch of Long Van System Solution JSC - Hanoi

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
184
First Reported
21 Oct 2025
Last Reported
25 Mar 2026, 18:00

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS131423
Branch of Long Van System Solution JSC - Hanoi
VN VN

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

14
Total IPs Monitored
947
Total Reports
67.6
Reports per IP

Network Context

This IP address belongs to Branch of Long Van System Solution JSC - Hanoi (AS131423), which manages 14 IP addresses in our monitoring system. Out of these, 947 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

92 %

Global Threat Ranking

This IP is more threatening than 92% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,733 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 184 avg: 23 ++

Network Comparison

Compared against 18 IPs in ASN 131423

Threat Level 10/10 network avg: 8.2 +
Total Reports 184 network avg: 59 ++
Network Branch of Long Van System Solution JSC - Hanoi has overall threat level 3/10

Geographic Comparison

Compared against 2,573 IPs in VN

Threat Level 10/10 country avg: 5.3 ++
Total Reports 184 country avg: 21 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,378 threat incidents tracked globally • Last 24h: 18,990 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,468 20.5%
  2. 02
    IN
    India IN
    29,138 15.6%
  3. 03
    CN
    China CN
    26,029 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,144 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,551 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,677 2.5%
  10. 10
    NL
    Netherlands NL
    4,358 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same subnet range, likely same network segment.

1 Related IPs
0/10 Avg Threat
23% Avg Confidence

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "103.2.225.33",
    "threat_level": 10,
    "confidence_score": 69,
    "total_reports": 184,
    "country_code": "VN",
    "isp_name": "Branch of Long Van System Solution JSC - Hanoi",
    "asn": "131423",
    "first_reported": "2025-10-21 06:18:30",
    "last_reported": "2026-03-25 18:00:34",
    "exported_at": "2026-06-09T10:57:22+02:00",
    "source": "https://reportedip.de/ip/103.2.225.33/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.