IP Address

91.202.233.33

IPv4 Public
TM TM
AS200593
Prospero Ooo
4,992 Reports
This IP is under Observation Suspicious activity detected - monitor closely
10/10 Threat
65% Confidence
4,992 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 10% High Threat
TM
TM Location
Prospero Ooo ASN 200593
4,992 Reports
Honeypot Data Source

Critical Alert

IP 91.202.233.33 is a Turkmenistan-based address operated by Prospero Ooo (AS200593) that represents one of the most prolific threat profiles documented in recent intelligence feeds, accumulating 4,992 independent abuse reports across automated honeypot sensors with a maximum threat rating of 10/10, driven predominantly by sustained SSH brute-force attack campaigns.

Analysis of the aggregated report data spanning October 2025 through March 2026 reveals a concentrated threat profile with SSH-related activity dominating the reported categories, supplemented by general hacking probes and brute-force credential attempts against exposed authentication endpoints. The detection network logged 20 separate honeypot sources reporting against this address, with associated fail2ban logs documenting a recidive pattern indicating repeated multi-jail offender status after the address accumulated multiple violation thresholds across sshd and recidive filters. Despite the extremely high report volume, the activity frequency metric of 0/10 suggests the most recent offensive operations concluded by March 2026, though the historical footprint indicates persistent, automated attacking infrastructure rather than isolated scanning activity.

SSH brute-force attacks systematically iterate authentication credentials against exposed sshd services, exploiting weak or default passwords to gain unauthorized server access. This address demonstrates the hallmarks of organized credential stuffing infrastructure, leveraging automation to scale password attempts across thousands of potential targets while evading detection through multi-source distribution patterns. An address with nearly five thousand independent reports represents a mature, established threat actor likely operating botnet-coordinated scanning operations rather than opportunistic individual probing.

Network defenders should treat IP 91.202.233.33 as a critical blocklist candidate given the volumetric threat history. Implementing automated blocking via intrusion-prevention tools such as fail2ban can proactively drop connections from known offenders. Exposed SSH services should enforce key-based authentication exclusively, disable root login, and consider non-standard port allocation to reduce surface area. Organizations with direct SSH exposure should review authentication logs for evidence of matching attack patterns and implement account lockout policies alongside multi-factor authentication to resiliently counter credential-guessing campaigns regardless of their originating source.

More threatening than 91% of monitored IPs

Threat Categories

SSH 27
Hacking 4
Brute-Force 4
Exploited Host 1

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Moderate Network Risk

The network hosting this IP (ASN 200593, operated by Prospero Ooo) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Continue monitoring for emerging patterns.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 0/10 Inactive
Confidence Score 64% High Confidence

Confidence History

11. Mar 2026 - 22. Mar 2026
65% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Exploited Host Honeypot 75%
Hacking Brute-Force Honeypot 75%
Hacking Brute-Force Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Hacking Brute-Force Honeypot x2 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%
SSH Honeypot 75%

Technical Details

Basic Information

IP Address
91.202.233.33
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class A

Geolocation

Country
TM TM
ASN
AS200593
ISP
Prospero Ooo

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
4,992
First Reported
31 Oct 2025
Last Reported
22 Mar 2026, 22:41

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS200593
Prospero Ooo
RU RU

Network Threat Assessment

4/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

10
Total IPs Monitored
5,122
Total Reports
512.2
Reports per IP

Network Context

This IP address belongs to Prospero Ooo (AS200593), which manages 10 IP addresses in our monitoring system. Out of these, 5,122 have been reported for suspicious activities, resulting in a network-wide threat level of 4/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

91 %

Global Threat Ranking

This IP is more threatening than 91% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 199,384 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 4,992 avg: 23 ++

Network Comparison

Compared against 15 IPs in ASN 200593

Threat Level 10/10 network avg: 6.5 ++
Total Reports 4,992 network avg: 342 ++
Network Prospero Ooo has overall threat level 4/10

Geographic Comparison

Compared against 10 IPs in TM

Threat Level 10/10 country avg: 7.8 +
Total Reports 4,992 country avg: 510 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

187,017 threat incidents tracked globally • Last 24h: 18,967 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,426 20.5%
  2. 02
    IN
    India IN
    28,977 15.5%
  3. 03
    CN
    China CN
    26,016 13.9%
  4. 04
    BR
    Brazil BR
    10,249 5.5%
  5. 05
    DE
    Germany DE
    7,139 3.8%
  6. 06
    SG
    Singapore SG
    6,475 3.5%
  7. 07
    ID
    Indonesia ID
    5,533 3%
  8. 08
    RU
    Russia RU
    4,701 2.5%
  9. 09
    PK
    Pakistan PK
    4,647 2.5%
  10. 10
    NL
    Netherlands NL
    4,355 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "91.202.233.33",
    "threat_level": 10,
    "confidence_score": 65,
    "total_reports": 4992,
    "country_code": "TM",
    "isp_name": "Prospero Ooo",
    "asn": "200593",
    "first_reported": "2025-10-31 16:43:14",
    "last_reported": "2026-03-22 22:41:27",
    "exported_at": "2026-06-09T08:16:20+02:00",
    "source": "https://reportedip.de/ip/91.202.233.33/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.