This IP address has been reported a total of
23
times from
22 distinct
sources.
1.53.99.35 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-13T19:20:06.847672+02:00 nbg-vs01-mailserver sshd-session[2395983]: Failed password for root ...
show more2026-09-13T19:20:06.847672+02:00 nbg-vs01-mailserver sshd-session[2395983]: Failed password for root from 1.53.99.35 port 48826 ssh2
2026-09-13T19:20:11.305434+02:00 nbg-vs01-mailserver sshd-session[2395983]: Failed password for root from 1.53.99.35 port 48826 ssh2
2026-09-13T19:20:14.041278+02:00 nbg-vs01-mailserver sshd-session[2395983]: Failed password for root from 1.53.99.35 port 48826 ssh2
...
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
2026-09-13T11:13:29.321164-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root fro ...
show more2026-09-13T11:13:29.321164-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root from 1.53.99.35 port 41830 ssh2
2026-09-13T11:13:33.955672-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root from 1.53.99.35 port 41830 ssh2
2026-09-13T11:13:37.621499-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root from 1.53.99.35 port 41830 ssh2
2026-09-13T11:13:41.008187-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root from 1.53.99.35 port 41830 ssh2
2026-09-13T11:13:43.973826-04:00 us-east2.cbz.pw sshd-session[2777197]: Failed password for root from 1.53.99.35 port 41830 ssh2
...
show less
2026-09-13T12:25:17.069605nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ss ...
show more2026-09-13T12:25:17.069605nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ssh2
2026-09-13T12:25:19.851703nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ssh2
2026-09-13T12:25:22.026184nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ssh2
2026-09-13T12:25:24.136507nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ssh2
2026-09-13T12:25:26.208928nar.lt sshd[25480]: Failed password for root from 1.53.99.35 port 50080 ssh2
show less
2026-09-13T11:43:33.110994+03:00 [HOSTNAME] sshd-session[3146797]: error: maximum authentication att ...
show more2026-09-13T11:43:33.110994+03:00 [HOSTNAME] sshd-session[3146797]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 58228 ssh2 [preauth]
2026-09-13T11:43:38.867510+03:00 [HOSTNAME] sshd-session[3146799]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 58234 ssh2 [preauth]
2026-09-13T11:43:43.685110+03:00 [HOSTNAME] sshd-session[3146852]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 57974 ssh2 [preauth]
...
show less
Sep 13 17:42:00 mags sshd-session[3414658]: error: maximum authentication attempts exceeded for root ...
show moreSep 13 17:42:00 mags sshd-session[3414658]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 49434 ssh2 [preauth]
Sep 13 17:42:08 mags sshd-session[3414672]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 45374 ssh2 [preauth]
Sep 13 17:42:16 mags sshd-session[3414676]: error: maximum authentication attempts exceeded for root from 1.53.99.35 port 47188 ssh2 [preauth]
Sep 13 17:42:27 mags sshd-session[3414681]: Invalid user admin from 1.53.99.35 port 57120
Sep 13 17:42:29 mags sshd-session[3414681]: error: maximum authentication attempts exceeded for invalid user admin from 1.53.99.35 port 57120 ssh2 [preauth]
Sep 13 17:42:35 mags sshd-session[3414683]: Invalid user admin from 1.53.99.35 port 51782
Sep 13 17:42:37 mags sshd-session[3414683]: error: maximum authentication attempts exceeded for invalid user admin from 1.53.99.35 port 51782 ssh2 [preauth]
...
show less
libssh2_1.11.1 client accessed with root/root creds. Recon phase: system arch, network config, proce ...
show morelibssh2_1.11.1 client accessed with root/root creds. Recon phase: system arch, network config, process enumeration. Searched for crypto miner processes via dual grep patterns (case-insensitive 'Miner'). Probed Telegram Desktop user data caches across home dirs. Targeted SMS infrastructure: GSM device nodes (/dev/ttyGSM*), SMS spool (/var/spool/sms/), SMSD config (/etc/smsd.conf*), qmuxd binary (/usr/bin/qmuxd). File hash search D877F783D5D3EF8C suggests malware inventory/persistence. CPU info and kernel queries indicate fingerprinting. Duration 107s, no mods/dl/persistence observed. No lateral movement. Profile: recon-focused botnet activity, environment assessment, credential/messaging data harvesting.
show less
Sep 13 08:06:20 community sshd[1647310]: Failed password for root from 1.53.99.35 port 47370 ssh2
Se ...
show moreSep 13 08:06:20 community sshd[1647310]: Failed password for root from 1.53.99.35 port 47370 ssh2
Sep 13 08:06:23 community sshd[1647310]: Failed password for root from 1.53.99.35 port 47370 ssh2
...
show less
SSH brute-force / unauthorized pre-auth probing against production node Manual-Audit. Filtered & dro ...
show moreSSH brute-force / unauthorized pre-auth probing against production node Manual-Audit. Filtered & dropped by iptables. Raw audit:
Manual audit command trigger
show less
2026-09-13T00:55:43.432104+00:00 kansas1 sshd[3056998]: Failed password for root from 1.53.99.35 por ...
show more2026-09-13T00:55:43.432104+00:00 kansas1 sshd[3056998]: Failed password for root from 1.53.99.35 port 40886 ssh2
2026-09-13T00:55:46.383962+00:00 kansas1 sshd[3056998]: Failed password for root from 1.53.99.35 port 40886 ssh2
2026-09-13T00:55:48.879895+00:00 kansas1 sshd[3056998]: Failed password for root from 1.53.99.35 port 40886 ssh2
...
show less