Report for IP: 199.45.154.75

Threat LevelHIGH51/1003 rule types across 2 attack categories
4 incidents on record · 3 rule types · confirmed on global blocklists · persistent 18-day campaign · last seen 9d ago · known internet scanner
PTR 75.154.45.199.censys-scanner.com
Org / ASN Censys, Inc.
Country 🇭🇰 Hong Kong
City Hong Kong, Kowloon
Timezone Asia/Hong_Kong
Internet ScannerCensys
Censys — academic/commercial internet scanner from University of Michigan that maps the entire IPv4 address space. Operates continuous internet-wide ZMap scans. All unsolicited scanning probes are treated as hostile traffic on this network regardless of stated purpose.

Attack Analysis

IDS: Blocklist — Dshield
This IP was reported to the DShield community blocklist by multiple independent security sensors worldwide. DShield aggregates firewall logs from thousands of contributors; IPs on this list are confirmed active attackers observed across many networks.
Listed on 3 threat-intelligence blocklists
  • DShield — DShield (SANS Internet Storm Center) lists the top attacking /24 networks by volume of firewall logs reported by thousands of sensors. It matches the whole /24, so this IP may be a neighbour of the actual attacker rather than the attacker itself.
  • FireHOL level1 — FireHOL level1 merges DShield, Spamhaus DROP, bogon ranges and Feodo botnet servers into one curated list built for very low false positives. When DShield or Spamhaus DROP also match, this one adds no independent evidence, since it already contains them.
  • FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
Curated, low-false-positive lists match, so this is a high-confidence bad address.

Reports (4)

Date Severity Description
21 Sep 2026 - 00:18 low DShield (top attacker /24s), FireHOL level1 (DShield+Spamhaus DROP+bogons+Feodo, merged, low-FP), FireHOL level2 (48h recent-attacker feed, large & volatile)
3 Sep 2026 - 17:58 high IDS: Blocklist — Dshield listed IP
3 Sep 2026 - 03:35 high IDS: Blocklist — Dshield listed IP — ET DROP Dshield Block Listed Source group 1
3 Sep 2026 - 03:34 high IDS: Blocklist — Dshield listed IP