Connecting

Address

91.67.88.100

Medium 30d list only

Suspicious SSH authentication attempts against monitored systems.

Triage

Risk score

how this score is made up
Risk score47/100
Detection volume+20Sensor corroboration+15Signal class+12Recency+0
Enrichment

Address intelligence

cached
CountryGermanyDE
City / regionWorms, Rheinland-Pfalz, GermanyEurope/Berlin
NetworkVodafone GmbHvodafone.de
ASNAS3209
Reverse DNSip-091-067-088-100.vkd76.pools.vodafone-ip.de
Detections5total observations
Reporting sensors3distinct collectors
First seen2026-09-11 22:33 GMT+827 days ago
Last seen2026-09-14 10:22 GMT+825 days ago
Blocklist window30d list only
Attribution

Reporting sensors

which collectors observed this address
  • SSH Sensor 041 observation · last 2026-09-14 10:22 GMT+8SSH
  • SSH Sensor 031 observation · last 2026-09-13 11:07 GMT+8SSH
  • SSH Sensor 013 observations · last 2026-09-11 22:33 GMT+8SSH
Sensor names are anonymised. Collector hostnames and log contents are never published.
Signals

Observation history

1 signal record
  • Suspicious SSH authentication attemptsMediumSSH abuse
    5 detections from 3 sensors · first seen 2026-09-11 22:33 GMT+8 · last seen 2026-09-14 10:22 GMT+8 (25 days ago) · active

    Suspicious SSH authentication attempts against monitored systems.

Abuse Radar publishes sanitized indicators only. Severity is a triage hint computed from detection volume, sensor corroboration, signal class and recency — it is not an attribution claim. See methodology.