IP Address

142.202.191.102

IPv4 Public
US US
AS398019
DYNU
2,118 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
62% Confidence
2,118 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
US
US Location
DYNU ASN 398019
2,118 Reports
Honeypot Data Source

Extreme Threat

IP 142.202.191.102 is a critical-risk address associated with sustained hacking activity, having accumulated 2,118 abuse reports within a two-month window and operating from a network infrastructure that exhibits concerning characteristics for a US-based IP. Despite a moderate 62% confidence score, the maximum threat level designation and concentration of honeypot sensor detections make this address a confirmed source of automated intrusion attempts that should be blocked at the network perimeter without hesitation.

The volume of reports filed against 142.202.191.102 is notably high for a short engagement window spanning January to February 2026, with all 20 most recent threat categorizations consistently identifying hacking activity. The IP originates from DYNU's autonomous system AS398019, and the consistent triggering of automated honeypot sensors indicates that the address is actively scanning and probing target networks rather than passively existing. The zero activity frequency rating against a ten-point scale suggests these attacks are intermittent or batched rather than continuous, which is typical of credential stuffing campaigns and vulnerability scanning tools that cycle through target ranges in defined intervals.

Hacking activity in this context encompasses automated exploitation attempts, unauthorized access probing, and vulnerability scanning conducted against exposed services such as SSH, Telnet, or web application interfaces. The real-world risk to an exposed organization is significant: successful intrusion can lead to data exfiltration, malware deployment, lateral movement within internal networks, or the establishment of persistent footholds for future campaigns. The honeypot detections confirm that 142.202.191.102 is running systematic reconnaissance and exploit attempts against internet-facing systems, making it a direct threat to any unpatched or misconfigured infrastructure it encounters.

Site operators should immediately block 142.202.191.102 at the firewall level and implement geolocation-based restrictions if the US region is not operationally required. Deploying fail2ban or equivalent intrusion prevention tools can automatically ban addresses that trigger authentication failure thresholds. Enforcing key-based authentication, disabling unused services, and maintaining strict patch management schedules will substantially reduce the attack surface that this address attempts to exploit. Continuous monitoring of abuse reports and integration of threat intelligence feeds will ensure this and similar addresses are promptly mitigated before they yield successful compromises.

More threatening than 90% of monitored IPs

Threat Categories

Hacking 30

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Reputable Network

This IP is hosted on a network (ASN 398019) with generally good reputation. The ISP DYNU maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 60% High Confidence

Confidence History

29. Jan 2026 - 13. Feb 2026
62% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Honeypot x39 75%
Hacking Honeypot x146 75%
Hacking Honeypot x257 75%
Hacking Honeypot x257 75%
Hacking Honeypot x125 75%
Hacking Honeypot x137 75%
Hacking Honeypot x7 75%
Hacking Honeypot x57 75%
Hacking Honeypot x247 75%
Hacking Honeypot x332 75%
Hacking Honeypot x237 75%
Hacking Honeypot x156 75%
Hacking Honeypot x99 75%
Hacking Honeypot x35 75%
Hacking Honeypot x9 75%
Hacking Honeypot x52 75%
Hacking Honeypot x182 75%
Hacking Honeypot x196 75%
Hacking Honeypot x126 75%
Hacking Honeypot x102 75%
Hacking Honeypot x151 75%
Hacking Honeypot x223 75%
Hacking Honeypot x98 75%
Hacking Honeypot x40 75%
Hacking Honeypot x170 75%
Hacking Honeypot x231 75%
Hacking Honeypot x139 75%
Hacking Honeypot x134 75%
Hacking Honeypot x95 75%
Hacking Honeypot x101 75%

Technical Details

Basic Information

IP Address
142.202.191.102
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class B

Geolocation

Country
US US
ASN
AS398019
ISP
DYNU

DNS Information

Reverse DNS
unassigned.142-202-191-102.spryt.net
PTR Record
Yes
Connection Type
Dynamic

Statistics

Total Reports
2,118
First Reported
20 Jan 2026
Last Reported
13 Feb 2026, 18:32

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS398019
Dynu Systems Incorporated
US US

Network Threat Assessment

2/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

13
Total IPs Monitored
23,933
Total Reports
1841
Reports per IP

Network Context

This IP address belongs to Dynu Systems Incorporated (AS398019), which manages 13 IP addresses in our monitoring system. Out of these, 23,933 have been reported for suspicious activities, resulting in a network-wide threat level of 2/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

90 %

Global Threat Ranking

This IP is more threatening than 90% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,353 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 2,118 avg: 23 ++

Network Comparison

Compared against 13 IPs in ASN 398019

Threat Level 10/10 network avg: 9.2 =
Total Reports 2,118 network avg: 1,841 +
Network DYNU has overall threat level 2/10

Geographic Comparison

Compared against 38,426 IPs in US

Threat Level 10/10 country avg: 5.9 ++
Total Reports 2,118 country avg: 41 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "142.202.191.102",
    "threat_level": 10,
    "confidence_score": 62,
    "total_reports": 2118,
    "country_code": "US",
    "isp_name": "DYNU",
    "asn": "398019",
    "first_reported": "2026-01-20 20:12:09",
    "last_reported": "2026-02-13 18:32:21",
    "exported_at": "2026-06-09T08:02:40+02:00",
    "source": "https://reportedip.de/ip/142.202.191.102/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.