IP Address

45.84.107.55

IPv4 Public Tor Exit Node
SE SE
AS214503
QuxLabs AB
395 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
69% Confidence
395 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
SE
SE Location
QuxLabs AB ASN 214503
395 Reports
Mixed Data Source

Critical Threat

IP address 45.84.107.55, allocated to QuxLabs AB in Sweden under autonomous system AS214503, presents a critical threat to exposed network infrastructure, scoring a maximum 10 out of 10 on assessed danger with a 69 percent confidence rating derived from 391 total abuse reports submitted over approximately nine months between September 2025 and May 2026. This address has been flagged across 15 automated honeypot sensors and 5 community-driven report sources, indicating sustained, high-volume malicious activity that crosses multiple threat categories. The dominant activity involves general hacking intrusion attempts, confirmed brute-force authentication attacks, reconnaissance port scans targeting Cisco ASA appliances, and a subset of specifically WordPress-oriented exploitation probes including configuration exposure, core vulnerabilities and backdoor installation attempts. The sheer breadth and volume of concurrent attack vectors make this IP a particularly versatile and dangerous actor in any environment where it is observed.

The pattern of activity detected against 45.84.107.55 reveals a multi-stage attack methodology consistent with automated compromise toolkits. Suricata-based detections specifically captured active SSH sessions on non-standard ports alongside the use of potentially unsafe SMBv1 protocols, suggesting the IP is not merely probing but actively exploiting or attempting to persist on targeted systems. Cisco ASA port scanning — a well-documented reconnaissance technique used to map perimeter defenses — appeared repeatedly alongside malware and exploit activity signatures, indicating the operator is systematically enumerating and exploiting vulnerable edge devices. The combination of brute-force SSH attempts, WordPress-specific exploitation attempts and SMBv1 abuse points to a threat actor leveraging a broad exploit toolkit rather than targeting a single service or vulnerability class. While the reporting window spans roughly nine months, the activity frequency rating of 5 out of 10 suggests the IP does not hammer targets continuously but sustains an ongoing presence with periodic bursts of activity.

More threatening than 92% of monitored IPs

Threat Categories

Hacking 23
Brute-Force 6
Exploited Host 5
Port Scan 4
SSH 3
WP Core Exploit 1

Technical Details

General hacking activity includes various intrusion attempts, exploitation of vulnerabilities, and unauthorized access attempts.

Recommended Mitigations

Keep systems patched, implement intrusion detection, and follow security best practices.

Behavioral Analysis

Activity Pattern: Consistent Activity

Steady malicious activity over 3 weeks indicates persistent threat actor operations.

First Observed 14. May 2026
Last Activity 8. June 2026
Recent (7 days) 3 incidents

Reputable Network

This IP is hosted on a network (ASN 214503) with generally good reputation. The ISP QuxLabs AB maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Long-term blocking recommended.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 69% High Confidence

Confidence History

21. Jan 2026 - 8. Jun 2026
69% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Exploited Host Honeypot x2 75%
Hacking Exploited Host Honeypot x2 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Brute-Force Community 75%
Hacking Exploited Host Port Scan Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Brute-Force Community 75%
Hacking SSH Honeypot x2 75%
Brute-Force Community 75%
Hacking Port Scan Honeypot x2 75%
Hacking Exploited Host Port Scan Honeypot x3 75%
Hacking Exploited Host Honeypot x2 75%
Hacking Honeypot 75%
Hacking SSH Honeypot x2 75%
Port Scan Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking WP Config Exposure WP Core Exploit +1 Community x5 75%
Hacking Honeypot x2 75%
Hacking Honeypot 75%
Hacking Honeypot x6 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%
Hacking Honeypot 75%

Technical Details

Basic Information

IP Address
45.84.107.55
IP Version
IPv4
Network Type
Public
Tor Network
Tor Exit Node
Network Class
Class A

Geolocation

Country
SE SE
ASN
AS214503
ISP
QuxLabs AB

DNS Information

Reverse DNS
exit-06.tor.r0cket.net
PTR Record
Yes
Connection Type
Static

Statistics

Total Reports
395
First Reported
9 Sep 2025
Last Reported
8 Jun 2026, 03:09

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS214503
QuxLabs AB
SE SE

Network Threat Assessment

2/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

18
Total IPs Monitored
2,890
Total Reports
160.6
Reports per IP

Network Context

This IP address belongs to QuxLabs AB (AS214503), which manages 18 IP addresses in our monitoring system. Out of these, 2,890 have been reported for suspicious activities, resulting in a network-wide threat level of 2/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

92 %

Global Threat Ranking

This IP is more threatening than 92% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,498 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 395 avg: 23 ++

Network Comparison

Compared against 19 IPs in ASN 214503

Threat Level 10/10 network avg: 7.2 +
Total Reports 395 network avg: 160 ++
Network QuxLabs AB has overall threat level 2/10

Geographic Comparison

Compared against 1,018 IPs in SE

Threat Level 10/10 country avg: 5.6 ++
Total Reports 395 country avg: 19 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,140 threat incidents tracked globally • Last 24h: 19,043 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,446 20.5%
  2. 02
    IN
    India IN
    29,023 15.5%
  3. 03
    CN
    China CN
    26,021 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,142 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,539 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,654 2.5%
  10. 10
    NL
    Netherlands NL
    4,356 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "45.84.107.55",
    "threat_level": 10,
    "confidence_score": 69,
    "total_reports": 395,
    "country_code": "SE",
    "isp_name": "QuxLabs AB",
    "asn": "214503",
    "first_reported": "2025-09-09 17:45:36",
    "last_reported": "2026-06-08 03:09:52",
    "exported_at": "2026-06-09T09:08:40+02:00",
    "source": "https://reportedip.de/ip/45.84.107.55/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.