IP Address

87.121.84.80

IPv4 Public
US US
AS215925
Vpsvault.host Ltd
210 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
97% Confidence
210 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
US
US Location
Vpsvault.host Ltd ASN 215925
210 Reports
Honeypot Data Source

Critical Threat

IP 87.121.84.80, registered to Vpsvault.host Ltd under ASN AS215925 and geolocated in the United States, presents a critical threat level of 10/10 with 97% confidence based on 210 abuse reports gathered from 20 automated honeypot sensors between March and April 2026. The dominant threat vector is SSH brute-force activity, with secondary hacking and general brute-force categories contributing to the overall risk profile. With an activity frequency rated at 3/10, this address represents a persistent, systematic attacker rather than a opportunistic probe, making it especially dangerous for any exposed SSH services.

The detection data reveals a relentless campaign targeting Secure Shell authentication across multiple victim systems. Fail2ban logs document repeated SSH brute-force violations ranging from 25 to 74 detections per instance, alongside consistent recidive classification indicating this address has been blocked multiple times for multi-jail offending. The volume of 210 total reports concentrated within a two-month window, combined with the recidive pattern, demonstrates an automated, high-volume credential attack infrastructure operated through a commercial hosting provider. The consistent targeting of SSH suggests the attacker is seeking to compromise Linux or Unix-based servers for purposes that may include data exfiltration, cryptomining, botnet recruitment, or lateral network movement.

SSH brute-force attacks represent one of the most common initial access vectors in server compromise, exploiting weak or default credentials to gain shell access. Once authenticated, an attacker can execute arbitrary commands, install persistent backdoors, escalate privileges, and pivot to adjacent systems. The automated nature of these attacks means servers with exposed SSH on standard ports and password-based authentication face constant, distributed guessing attempts that eventually succeed against insufficiently protected deployments. The recidive behavior observed here indicates standard blocklists alone have proven insufficient to deter this actor, requiring more robust countermeasures.

Organizations with SSH services exposed to this IP address should block 87.121.84.80 at the network perimeter immediately. Beyond simple blocking, administrators should disable password-based SSH authentication entirely and deploy public key authentication with strong key pairs. Changing the default SSH listening port reduces automated attack surface significantly. Implementing fail2ban or similar dynamic blocklisting tools provides automated response to repeated authentication failures. Enforcing multi-factor authentication for privileged SSH access adds a critical security layer even if credentials are compromised. Regular monitoring of authentication logs for unusual source IPs and implementing account lockout policies further harden defenses against credential-based intrusion attempts.

More threatening than 99% of monitored IPs

Threat Categories

SSH 27
Hacking 8
Brute-Force 8

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Reputable Network

This IP is hosted on a network (ASN 215925) with generally good reputation. The ISP Vpsvault.host Ltd maintains standard security practices.

The malicious activity may represent an isolated compromised system rather than systematic abuse.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 3/10 Low
Confidence Score 79% Verified

Confidence History

19. Apr 2026 - 21. Apr 2026
97% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Brute-Force Honeypot 75%
Hacking Brute-Force Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
Hacking Brute-Force Honeypot 75%
SSH Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
87.121.84.80
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
US US
ASN
AS215925
ISP
Vpsvault.host Ltd

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
210
First Reported
2 Mar 2026
Last Reported
21 Apr 2026, 01:01

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS215925
Vpsvault.host Ltd
US US

Network Threat Assessment

3/10
This network appears to be relatively clean with very low threat indicators.

Network Statistics

119
Total IPs Monitored
27,203
Total Reports
228.6
Reports per IP

Network Context

This IP address belongs to Vpsvault.host Ltd (AS215925), which manages 119 IP addresses in our monitoring system. Out of these, 27,203 have been reported for suspicious activities, resulting in a network-wide threat level of 3/10.

Network status: This network appears to be well-maintained with low threat indicators.

Comparative Analysis

How this IP compares to others in our threat intelligence database

99 %

Global Threat Ranking

This IP is more threatening than 99% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,468 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 210 avg: 23 ++

Network Comparison

Compared against 157 IPs in ASN 215925

Threat Level 10/10 network avg: 8.4 +
Total Reports 210 network avg: 184 =
Network Vpsvault.host Ltd has overall threat level 3/10

Geographic Comparison

Compared against 38,446 IPs in US

Threat Level 10/10 country avg: 5.9 ++
Total Reports 210 country avg: 41 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,140 threat incidents tracked globally • Last 24h: 19,043 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US THIS IP
    38,446 20.5%
  2. 02
    IN
    India IN
    29,023 15.5%
  3. 03
    CN
    China CN
    26,021 13.9%
  4. 04
    BR
    Brazil BR
    10,256 5.5%
  5. 05
    DE
    Germany DE
    7,142 3.8%
  6. 06
    SG
    Singapore SG
    6,476 3.5%
  7. 07
    ID
    Indonesia ID
    5,539 3%
  8. 08
    RU
    Russia RU
    4,703 2.5%
  9. 09
    PK
    Pakistan PK
    4,654 2.5%
  10. 10
    NL
    Netherlands NL
    4,356 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9/10 Avg Threat
96% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

IPs from the same subnet range, likely same network segment.

20 Related IPs
9/10 Avg Threat
96% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "87.121.84.80",
    "threat_level": 10,
    "confidence_score": 97,
    "total_reports": 210,
    "country_code": "US",
    "isp_name": "Vpsvault.host Ltd",
    "asn": "215925",
    "first_reported": "2026-03-02 04:52:23",
    "last_reported": "2026-04-21 01:01:55",
    "exported_at": "2026-06-09T08:50:33+02:00",
    "source": "https://reportedip.de/ip/87.121.84.80/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.