Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
Repeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed ...
show moreRepeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed authentication attempts from this IP across an extended period.
show less
Brute-Force
SSH
Anonymous
Repeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed ...
show moreRepeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed authentication attempts from this IP across an extended period.
show less
2026-08-12T11:31:02.615511+02:00 flux-acorn-twmmtn sshd-session[12206]: Invalid user teams from 5.19 ...
show more2026-08-12T11:31:02.615511+02:00 flux-acorn-twmmtn sshd-session[12206]: Invalid user teams from 5.199.130.61 port 60200
...
show less
2026-08-12T05:13:20.666609-04:00 www3 sshd[1418794]: Invalid user admin from 5.199.130.61 port 50380 ...
show more2026-08-12T05:13:20.666609-04:00 www3 sshd[1418794]: Invalid user admin from 5.199.130.61 port 50380
2026-08-12T05:13:20.762988-04:00 www3 sshd[1418794]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61
2026-08-12T05:13:22.892830-04:00 www3 sshd[1418794]: Failed password for invalid user admin from 5.199.130.61 port 50380 ssh2
2026-08-12T05:13:22.722855-04:00 www3 sshd[1418800]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61 user=root
2026-08-12T05:13:24.462898-04:00 www3 sshd[1418800]: Failed password for root from 5.199.130.61 port 35502 ssh2
...
show less
Aug 12 11:11:38 odin sshd[26946]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreAug 12 11:11:38 odin sshd[26946]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61
Aug 12 11:11:40 odin sshd[26946]: Failed password for invalid user admin from 5.199.130.61 port 60970 ssh2
Aug 12 11:11:42 odin sshd[26955]: Failed password for root from 5.199.130.61 port 60984 ssh2
show less
2026-08-12T11:07:14.590891+02:00 ns3124905 sshd-session[3299609]: pam_unix(sshd:auth): authenticatio ...
show more2026-08-12T11:07:14.590891+02:00 ns3124905 sshd-session[3299609]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61 user=root
2026-08-12T11:07:16.909418+02:00 ns3124905 sshd-session[3299609]: Failed password for root from 5.199.130.61 port 39478 ssh2
2026-08-12T11:07:18.924103+02:00 ns3124905 sshd-session[3299633]: Invalid user admin from 5.199.130.61 port 39492
...
show less
Failed password for invalid user Aug 11 13:30:34 port [preauth]
Brute-Force
SSH
Anonymous
(sshd) Failed SSH login from 5.199.130.61 (DE/Germany/vps2635487.fastwebserver.de): 5 in the last 30 ...
show more(sshd) Failed SSH login from 5.199.130.61 (DE/Germany/vps2635487.fastwebserver.de): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: 2026-08-11T15:07:32.098370+02:00 web28.sier.online sshd[2036771]: Invalid user admin2026 from 5.199.130.61 port 37564
2026-08-11T15:07:32.164888+02:00 web28.sier.online sshd[2036771]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61
2026-08-11T15:07:34.173519+02:00 web28.sier.online sshd[2036771]: Failed password for invalid user admin2026 from 5.199.130.61 port 37564 ssh2
2026-08-11T15:10:26.660138+02:00 web28.sier.online sshd[2038263]: Invalid user admin2026 from 5.199.130.61 port 59466
2026-08-11T15:10:26.676343+02:00 web28.sier.online sshd[2038263]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=5.199.130.61
show less
Aug 10 18:27:12 wh02 sshd[528546]: Connection closed by authenticating user progameservers 5.199.130 ...
show moreAug 10 18:27:12 wh02 sshd[528546]: Connection closed by authenticating user progameservers 5.199.130.61 port 35498 [preauth]
Aug 10 18:55:47 wh02 sshd[574204]: Connection closed by authenticating user clicknetworks 5.199.130.61 port 53754 [preauth]
Aug 11 11:16:10 wh02 sshd[2825097]: Invalid user ubuntu from 5.199.130.61 port 59634
Aug 11 11:16:10 wh02 sshd[2825097]: Connection closed by invalid user ubuntu 5.199.130.61 port 59634 [preauth]
Aug 11 11:16:32 wh02 sshd[2825835]: Invalid user ubuntu from 5.199.130.61 port 57440
Aug 11 11:16:32 wh02 sshd[2825835]: Connection closed by invalid user ubuntu 5.199.130.61 port 57440 [preauth]
Aug 11 11:22:12 wh02 sshd[2827801]: Invalid user ubuntu from 5.199.130.61 port 42118
Aug 11 11:22:12 wh02 sshd[2827801]: Connection closed by invalid user ubuntu 5.199.130.61 port 42118 [preauth]
Aug 11 13:34:10 wh02 sshd[3041516]: Invalid user benschoeffel from 5.199.130.61 port 58110
Aug 11 13:34:10 wh02 sshd[3041516]: Connection closed by invalid user be
show less
Brute-Force
Exploited Host
SSH
Showing 1 to
15
of 159 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ