This IP address has been reported a total of
50
times from
37 distinct
sources.
103.148.28.235 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(sshd) Failed SSH login from 103.148.28.235 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Dir ...
show more(sshd) Failed SSH login from 103.148.28.235 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 6 09:59:22 14379 sshd[22204]: Did not receive identification string from 103.148.28.235 port 53110
Jun 6 09:59:24 14379 sshd[22247]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
Jun 6 09:59:26 14379 sshd[22247]: Failed password for root from 103.148.28.235 port 53122 ssh2
Jun 6 09:59:29 14379 sshd[22257]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
Jun 6 09:59:31 14379 sshd[22257]: Failed password for root from 103.148.28.235 port 40748 ssh2
show less
Jun 5 01:27:07 shu sshd[28292]: Failed password for root from 103.148.28.235 port 53988 ssh2
Jun 5 ...
show moreJun 5 01:27:07 shu sshd[28292]: Failed password for root from 103.148.28.235 port 53988 ssh2
Jun 5 01:27:11 shu sshd[28345]: Failed password for root from 103.148.28.235 port 53992 ssh2
...
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
Honeypot [fra-de-honeypot]: Empty payload (likely service probe); 5022 [1] TCP
Reported by DisPaisy ...
show moreHoneypot [fra-de-honeypot]: Empty payload (likely service probe); 5022 [1] TCP
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
2026-05-27T23:17:58.195635+02:00 personaldiamant3 sshd[2105286]: Failed password for root from 103.1 ...
show more2026-05-27T23:17:58.195635+02:00 personaldiamant3 sshd[2105286]: Failed password for root from 103.148.28.235 port 38032 ssh2
2026-05-27T23:18:01.467861+02:00 personaldiamant3 sshd[2105290]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
2026-05-27T23:18:02.877252+02:00 personaldiamant3 sshd[2105290]: Failed password for root from 103.148.28.235 port 37644 ssh2
...
show less
(sshd) Failed SSH login from 103.148.28.235 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Dir ...
show more(sshd) Failed SSH login from 103.148.28.235 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 27 02:17:14 20380 sshd[28778]: Did not receive identification string from 103.148.28.235 port 49952
May 27 02:17:16 20380 sshd[28779]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 27 02:17:18 20380 sshd[28779]: Failed password for root from 103.148.28.235 port 49958 ssh2
May 27 02:17:20 20380 sshd[28786]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 27 02:17:21 20380 sshd[28786]: Failed password for root from 103.148.28.235 port 46060 ssh2
show less
103.148.28.235 (ID/Indonesia/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; ...
show more103.148.28.235 (ID/Indonesia/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: May 19 10:40:08 15442 sshd[3820]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 19 10:40:10 15442 sshd[3820]: Failed password for root from 103.148.28.235 port 55364 ssh2
May 19 10:40:12 15442 sshd[3822]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 19 10:35:42 15442 sshd[3399]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.106.65.131 user=root
May 19 10:35:44 15442 sshd[3399]: Failed password for root from 170.106.65.131 port 38096 ssh2
IP Addresses Blocked:
show less
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login atte ...
show moreAutomated report: SSH brute force detected. This IP exceeded the allowed number of failed login attempts (3 attempts).
show less
2026-05-16T17:33:38.597462 dc-eu-ger-fra-001.aki-solutions.local sshd[1055764]: Failed password for ...
show more2026-05-16T17:33:38.597462 dc-eu-ger-fra-001.aki-solutions.local sshd[1055764]: Failed password for root from 103.148.28.235 port 39004 ssh2
2026-05-16T17:33:40.571079 dc-eu-ger-fra-001.aki-solutions.local sshd[1057965]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
2026-05-16T17:33:42.551479 dc-eu-ger-fra-001.aki-solutions.local sshd[1057965]: Failed password for root from 103.148.28.235 port 59356 ssh2
...
show less
(sshd) Failed SSH login from 103.148.28.235 (ID/-/-): 5 in the last 3600 secs; Ports: *; Direction: ...
show more(sshd) Failed SSH login from 103.148.28.235 (ID/-/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 15 18:49:26 14592 sshd[15349]: Did not receive identification string from 103.148.28.235 port 35220
May 15 18:49:28 14592 sshd[15351]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 15 18:49:30 14592 sshd[15351]: Failed password for root from 103.148.28.235 port 35226 ssh2
May 15 18:49:32 14592 sshd[15353]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.148.28.235 user=root
May 15 18:49:34 14592 sshd[15353]: Failed password for root from 103.148.28.235 port 35016 ssh2
show less
Brute-Force
SSH
Showing 1 to
15
of 50 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ