IP Address

196.191.254.26

IPv4 Public
ET ET
AS24757
Ethiopian Telecommunication Corporation
408 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
94% Confidence
408 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
ET
ET Location
Ethiopian Telecommunicati... ASN 24757
408 Reports
Honeypot Data Source

Severe Risk

IP 196.191.254.26 is a critical-risk address associated with an exploited host that has generated 408 abuse reports, indicating sustained malicious activity originating from a compromised system within Ethiopian Telecommunication Corporation's network (ASN AS24757). The IP has been flagged with a maximum threat score of 10/10 and an activity frequency rating of 8/10, reflecting continuous engagement in malware and exploit-related operations over the December 2025 reporting window. Detection across 20 independent automated honeypot sensors confirms a 94% confidence level that this address is actively participating in hostile operations without the knowledge of its legitimate operator.

The 408 total reports and high activity frequency establish this as one of the most actively reported addresses in the observed timeframe. All 20 report sources are automated honeypot sensors, which detected exploit-oriented activity consistent with a compromised host being weaponized for external attacks. Ethiopian Telecommunication Corporation operates the underlying network infrastructure, but the address itself shows clear signs of having fallen under unauthorized control. The geographic attribution to Ethiopia (ET) and the concentration of identical honeypot detections point to automated scanning and exploitation activity rather than isolated manual attempts.

An exploited host presents a concrete and serious threat because the machine is being weaponized remotely, typically through malware or remote access tooling, while its owner remains unaware. Attackers leverage such compromised infrastructure to conduct scanning, exploit delivery, credential abuse or further propagation of malicious payloads against other targets globally. For network defenders, an exploited host in a foreign network means attacks may carry the weight of a seemingly legitimate residential or corporate IP, making detection and attribution harder for victims' defensive systems. The real-world risk extends beyond this single address: it represents a node in a potential botnet or attack chain that could affect any exposed service on the internet.

Site operators should immediately block IP 196.191.254.26 at the network perimeter and monitor logs for any related attempt patterns. Deploying or strengthening rate-limiting and brute-force protection mechanisms—such as fail2ban or equivalent tools—reduces the impact of similar scanning activity from this source. Enforcing strong authentication on exposed services, applying least-privilege access controls and maintaining up-to-date patching across all internet-facing systems limits the effectiveness of any exploitation attempts. Organizations experiencing repeated contact from this address should consider filing an abuse report with Ethiopian Telecommunication Corporation to facilitate remediation of the compromised host at its source.

More threatening than 98% of monitored IPs

Threat Categories

Exploited Host 30

Technical Details

This IP belongs to a compromised system being used as an attack platform without the owner's knowledge.

Recommended Mitigations

Block the IP and consider notifying the hosting provider or system owner about the compromise.

Moderate Network Risk

The network hosting this IP (ASN 24757, operated by Ethiopian Telecommunication Corporation) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 59% High Confidence

Confidence History

28. Dec 2025
94% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%
Exploited Host Honeypot 75%

Technical Details

Basic Information

IP Address
196.191.254.26
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
ET ET
ASN
AS24757
ISP
Ethiopian Telecommunication Corporation

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
408
First Reported
27 Dec 2025
Last Reported
28 Dec 2025, 05:11

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS24757
Ethiopian Telecommunication Corporation
ET ET

Network Threat Assessment

5/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

178
Total IPs Monitored
2,256
Total Reports
12.7
Reports per IP

Network Context

This IP address belongs to Ethiopian Telecommunication Corporation (AS24757), which manages 178 IP addresses in our monitoring system. Out of these, 2,256 have been reported for suspicious activities, resulting in a network-wide threat level of 5/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

98 %

Global Threat Ranking

This IP is more threatening than 98% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,756 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 408 avg: 23 ++

Network Comparison

Compared against 231 IPs in ASN 24757

Threat Level 10/10 network avg: 5.8 ++
Total Reports 408 network avg: 10 ++
Network Ethiopian Telecommunication Corporation has overall threat level 5/10

Geographic Comparison

Compared against 250 IPs in ET

Threat Level 10/10 country avg: 5.8 ++
Total Reports 408 country avg: 10 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,378 threat incidents tracked globally • Last 24h: 18,990 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,468 20.5%
  2. 02
    IN
    India IN
    29,138 15.6%
  3. 03
    CN
    China CN
    26,029 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,144 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,551 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,677 2.5%
  10. 10
    NL
    Netherlands NL
    4,358 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.4/10 Avg Threat
83% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

1 Related IPs
0/10 Avg Threat
30% Avg Confidence

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "196.191.254.26",
    "threat_level": 10,
    "confidence_score": 94,
    "total_reports": 408,
    "country_code": "ET",
    "isp_name": "Ethiopian Telecommunication Corporation",
    "asn": "24757",
    "first_reported": "2025-12-27 14:29:55",
    "last_reported": "2025-12-28 05:11:19",
    "exported_at": "2026-06-09T11:06:03+02:00",
    "source": "https://reportedip.de/ip/196.191.254.26/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.