This IP address has been reported a total of
29
times from
24 distinct
sources.
103.99.214.131 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-15T08:23:50.154363+02:00 sshadmin sshd-session[51210]: Invalid user super from 103.99.214.13 ...
show more2026-06-15T08:23:50.154363+02:00 sshadmin sshd-session[51210]: Invalid user super from 103.99.214.131 port 34588
2026-06-15T08:27:59.161919+02:00 sshadmin sshd-session[51240]: Invalid user adminuser from 103.99.214.131 port 52350
2026-06-15T08:30:00.546429+02:00 sshadmin sshd-session[51246]: Invalid user sysadmin from 103.99.214.131 port 40524
2026-06-15T08:31:55.403459+02:00 sshadmin sshd-session[51252]: Invalid user admin from 103.99.214.131 port 38552
2026-06-15T08:33:59.855853+02:00 sshadmin sshd-session[51265]: Invalid user azureuser from 103.99.214.131 port 49516
...
show less
Jun 15 03:03:25 proxy-03 sshd[395670]: Invalid user broker from 103.99.214.131 port 49594
Jun 15 03: ...
show moreJun 15 03:03:25 proxy-03 sshd[395670]: Invalid user broker from 103.99.214.131 port 49594
Jun 15 03:03:25 proxy-03 sshd[395670]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 15 03:03:28 proxy-03 sshd[395670]: Failed password for invalid user broker from 103.99.214.131 port 49594 ssh2
Jun 15 03:03:25 proxy-03 sshd[395670]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 15 03:03:28 proxy-03 sshd[395670]: Failed password for invalid user broker from 103.99.214.131 port 49594 ssh2
...
show less
Jun 15 02:26:29 proxy-03 sshd[332426]: Failed password for invalid user oldblog from 103.99.214.131 ...
show moreJun 15 02:26:29 proxy-03 sshd[332426]: Failed password for invalid user oldblog from 103.99.214.131 port 41816 ssh2
Jun 15 02:30:37 proxy-03 sshd[338162]: Invalid user rrd from 103.99.214.131 port 36152
Jun 15 02:30:37 proxy-03 sshd[338162]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 15 02:30:40 proxy-03 sshd[338162]: Failed password for invalid user rrd from 103.99.214.131 port 36152 ssh2
Jun 15 02:32:46 proxy-03 sshd[341170]: Invalid user tomcat from 103.99.214.131 port 35284
...
show less
CSF/LFD blocked 103.99.214.131 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH ...
show moreCSF/LFD blocked 103.99.214.131 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH login from 103.99.214.131 (ID/Indonesia/-): 5 in the last 3600 secs. Evidence: Jun 15 00:17:27 paladin sshd-session[2705209]: Invalid user oldblog from 103.99.214.131 port 46186
show less
Jun 14 23:25:09 digamma sshd[239839]: pam_unix(sshd:auth): authentication failure; logname= uid=0 eu ...
show moreJun 14 23:25:09 digamma sshd[239839]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 14 23:25:11 digamma sshd[239839]: Failed password for invalid user oldblog from 103.99.214.131 port 52470 ssh2
Jun 14 23:30:24 digamma sshd[239905]: Invalid user rrd from 103.99.214.131 port 44756
...
show less
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show moreMalicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-15 06:27:32 UTC
Log evidence:
06/15/2026-06:27:31.861129 [**] [1:1000090:1] POLICY Unauthorized Management Port Access [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 103.99.214.131:57398 -> 185.127.18.66:22
show less
Port Scan
Brute-Force
Anonymous
2026-06-15T04:36:13.430370+00:00 ephialtes2 sshd[1020494]: Failed password for invalid user v2 from ...
show more2026-06-15T04:36:13.430370+00:00 ephialtes2 sshd[1020494]: Failed password for invalid user v2 from 103.99.214.131 port 50110 ssh2
2026-06-15T05:07:23.819581+00:00 ephialtes2 sshd[1029323]: Invalid user morgan from 103.99.214.131 port 57904
2026-06-15T05:07:23.819581+00:00 ephialtes2 sshd[1029323]: Invalid user morgan from 103.99.214.131 port 57904
2026-06-15T05:07:23.821146+00:00 ephialtes2 sshd[1029323]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
2026-06-15T05:07:26.255931+00:00 ephialtes2 sshd[1029323]: Failed password for invalid user morgan from 103.99.214.131 port 57904 ssh2
...
show less
2026-06-15T06:41:31.157365+02:00 epyc01 sshd-session[266278]: Connection from 103.99.214.131 port 38 ...
show more2026-06-15T06:41:31.157365+02:00 epyc01 sshd-session[266278]: Connection from 103.99.214.131 port 38876 on 5.231.248.234 port 22 rdomain ""
2026-06-15T06:41:32.078496+02:00 epyc01 sshd-session[266278]: Invalid user geo from 103.99.214.131 port 38876
2026-06-15T06:43:24.412665+02:00 epyc01 sshd-session[267651]: Connection from 103.99.214.131 port 47212 on 5.231.248.234 port 22 rdomain ""
2026-06-15T06:43:25.332129+02:00 epyc01 sshd-session[267651]: Invalid user pif from 103.99.214.131 port 47212
...
show less
Brute-Force
SSH
Anonymous
2026-06-15T04:27:37.008743+00:00 ephialtes2 sshd[1018025]: Failed password for invalid user market f ...
show more2026-06-15T04:27:37.008743+00:00 ephialtes2 sshd[1018025]: Failed password for invalid user market from 103.99.214.131 port 34696 ssh2
2026-06-15T04:34:03.514268+00:00 ephialtes2 sshd[1019854]: Invalid user notification from 103.99.214.131 port 57236
2026-06-15T04:34:03.515662+00:00 ephialtes2 sshd[1019854]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
2026-06-15T04:34:05.388168+00:00 ephialtes2 sshd[1019854]: Failed password for invalid user notification from 103.99.214.131 port 57236 ssh2
2026-06-15T04:36:11.651864+00:00 ephialtes2 sshd[1020494]: Invalid user v2 from 103.99.214.131 port 50110
...
show less
Jun 14 22:25:52 tweety sshd[2164236]: pam_unix(sshd:auth): authentication failure; logname= uid=0 eu ...
show moreJun 14 22:25:52 tweety sshd[2164236]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 14 22:25:54 tweety sshd[2164236]: Failed password for invalid user market from 103.99.214.131 port 37474 ssh2
Jun 14 22:33:47 tweety sshd[2165406]: Invalid user notification from 103.99.214.131 port 57026
...
show less
2026-06-14T21:23:15.884738-07:00 server.vexstria.pro sshd[3520808]: pam_unix(sshd:auth): authenticat ...
show more2026-06-14T21:23:15.884738-07:00 server.vexstria.pro sshd[3520808]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
2026-06-14T21:23:18.128835-07:00 server.vexstria.pro sshd[3520808]: Failed password for invalid user market from 103.99.214.131 port 50802 ssh2
2026-06-14T21:33:23.109734-07:00 server.vexstria.pro sshd[3727447]: Invalid user notification from 103.99.214.131 port 45212
...
show less
Jun 15 04:29:50 fail2ban sshd[3744059]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJun 15 04:29:50 fail2ban sshd[3744059]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.99.214.131
Jun 15 04:29:51 fail2ban sshd[3744059]: Failed password for invalid user market from 103.99.214.131 port 53566 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 29 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ