> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Crime Score Test IP (146.59.103.250)

> A controlled test server used to validate Crime Score detection

`146.59.103.250` is a deliberately noisy test server. It is used to check how the OneFirewall Crime Score reacts to an IP address that behaves like a malicious actor.

<Warning>
  This IP is **not a real threat actor**. It is a controlled test asset hosted by a OneFirewall Partner. It is not intended for use by external parties.
</Warning>

***

## Overview

| Item             | Value                 |
| ---------------- | --------------------- |
| IP address       | `146.59.103.250`      |
| Type             | Virtual server        |
| Hosting provider | OVH                   |
| Location         | Poland                |
| Operated by      | A OneFirewall Partner |
| Purpose          | Crime Score test case |

***

## Purpose

The server is designed to perform random activity that IDS and IPS systems can intercept and classify as malicious. Because the activity is generated on purpose and in a controlled way, the address gives a known reference point to verify that:

* Sensors and IDS report the behavior as expected.
* The report reaches OneFirewall and is turned into threat intelligence.
* The [Crime Score](/essentials/crime-score) of the address is calculated and updated.
* Feeds and Preventive Mode react to the resulting score.

***

## What to expect

* The address may appear in your logs, alerts or feeds with a raised Crime Score.
* The activity varies and is not predictable. It can trigger different IDS signatures at different times.
* The score can change over time as new reports arrive and old ones age.

This does not indicate a compromise of your environment.

***

## How to handle it

* **Report it:** if you see this IP in your logs, report it as a malicious actor. Reports are what allow the Crime Score to be tested end to end.
* **Testing the platform:** use the address as a known-bad reference when validating detection, scoring and blocking.
* **Allow-listing:** do not allow-list the address if you want it to serve as a test case in your own environment.

***

## For ISPs and law enforcement

<Info>
  This IP is controlled and is **not** used to cause any real damage. Its activity is designed only to test the detection capabilities of security systems.
</Info>

* The traffic is generated on purpose, under the control of a OneFirewall Partner.
* No real attack, intrusion or data theft is carried out.
* No action against the hosting provider or the operator is needed.

***

## Important notes

* The server is hosted by a OneFirewall Partner and is not available as a service to third parties.
* For questions, contact [support@onefirewall.com](mailto:support@onefirewall.com).
