False Statement Mapping
| IP Address | Incorrect Statement | Why It Is Incorrect | Correct Classification |
| 193.142.146.112 | Phishing & credential harvesting infra | Only SSH brute-force and port scanning seen. No phishing pages, kits, or campaigns. Activity is old. | Historical SSH brute-force / scanning (inactive) |
| 104.244.72.115 | Cloud-hosted VPS (can be abused) | This is only infrastructure context. IP shows real malicious activity, not just “can be abused.” | Active malicious IP (web attacks, brute-force, TOR abuse) |
| 51.195.102.77 | Public VPS, noisy traffic | No alerts, scans, or abuse reported. “Noisy” is not supported by evidence. | Clean cloud IP (no malicious activity) |
| 167.71.12.34 | Cloud provider scanning behavior | Scanning came from abused cloud VM, not the cloud provider itself. No recent activity. | Historical abuse from cloud-hosted IP |
| 139.59.64.89 | Temporary / short-lived IP | No evidence of IP rotation or short lifecycle. Cloud hosting alone is not proof. | Legitimate cloud IP (stable, clean) |