Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 106.13.163.96:
This IP address has been reported a total of
293
times from
186 distinct
sources.
106.13.163.96 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 82
reports;
United States of America
with 41
reports;
France
with 22
reports.
The most common categories in these recent reports were:
SSH
245
times;
Brute-Force
228
times;
Port Scan
52
times;
Hacking
12
times;
Web App Attack
4
times;
Other
16
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login atte ...
show moreAutomated report: SSH brute force detected. This IP exceeded the allowed number of failed login attempts (3 attempts).
show less
Honeypot [fra-de-honeypot]: Empty payload (likely service probe); 22222 [1] TCP
Reported by DisPaisy ...
show moreHoneypot [fra-de-honeypot]: Empty payload (likely service probe); 22222 [1] TCP
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Aug 24 13:31:44 obsidian sshd[3543309]: Failed password for root from 106.13.163.96 port 58128 ssh2
...
show moreAug 24 13:31:44 obsidian sshd[3543309]: Failed password for root from 106.13.163.96 port 58128 ssh2
Aug 24 13:31:46 obsidian sshd[3543367]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.13.163.96 user=root
Aug 24 13:31:48 obsidian sshd[3543367]: Failed password for root from 106.13.163.96 port 59764 ssh2
...
show less
🛡️ Honeypot [bsts-tpot-hive]: Brute-force attack detected on 22/SSH
• Credentials: root:------fuck- ...
show more🛡️ Honeypot [bsts-tpot-hive]: Brute-force attack detected on 22/SSH
• Credentials: root:------fuck------, root:root123456, root:h3c.com!
• Number of login attempts: 3
• 1 command(s) were executed during the session
• Client: SSH-2.0-Go
show less
2026-08-24T04:39:59.250687 ns2.open-bs.ru sshd-session[75741]: Failed password for root from 106.13. ...
show more2026-08-24T04:39:59.250687 ns2.open-bs.ru sshd-session[75741]: Failed password for root from 106.13.163.96 port 39972 ssh2
2026-08-24T04:40:02.446429 ns2.open-bs.ru sshd-session[75744]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.13.163.96 user=root
2026-08-24T04:40:04.011191 ns2.open-bs.ru sshd-session[75744]: Failed password for root from 106.13.163.96 port 41870 ssh2
...
show less
Failed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 16/100 (low) ...
show moreFailed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 16/100 (low) | Phase: reconnaissance (pre-auth probing / scanning)
Failed auth: 6 (6 bad password, 0 invalid user) | 0 success | 14 total SSH log events | seen on 2 sensor(s)
Origin: China (CN) | AS38365 Beijing Baidu Netcom Science and Technology Co., Ltd. | 106.13.163.0/24
First seen: 2026-08-04 22:21:31 UTC | Last seen: 2026-08-24 00:09:34 UTC
Source: Linux OpenSSH journalctl telemetry, multi-sensor CERT honeypot.
show less
2026-08-24T02:07:34.167699+08:00 [Host] sshd[119309]: error: kex_exchange_identification: Connection ...
show more2026-08-24T02:07:34.167699+08:00 [Host] sshd[119309]: error: kex_exchange_identification: Connection closed by remote host
2026-08-24T02:07:34.167768+08:00 [Host] sshd[119309]: Connection closed by 106.13.163.96 port 41518
2026-08-24T02:07:38.820644+08:00 [Host] sshd[119310]: Connection closed by authenticating user root 106.13.163.96 port 41598 [preauth]
...
show less
[mirai-detector honeypot] Inbound attack against our honeypot on tcp/2323 (telnet).
Tried credential ...
show more[mirai-detector honeypot] Inbound attack against our honeypot on tcp/2323 (telnet).
Tried credentials: b'':b''
show less