This IP address has been reported a total of
24
times from
23 distinct
sources.
104.155.48.101 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 7
reports;
France
with 4
reports;
Germany
with 2
reports.
The most common categories in these recent reports were:
Brute-Force
12
times;
Port Scan
6
times;
Email Spam
5
times;
Hacking
5
times;
FTP Brute-Force
4
times;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
PortSentry honeypot: unsolicited TCP connection to closed decoy port 23 (Telnet) on a host running n ...
show morePortSentry honeypot: unsolicited TCP connection to closed decoy port 23 (Telnet) on a host running no such service. Automated port-scan detection at 2026-10-05T12:13:24Z.
show less
(ftpd) Failed FTP login from 104.155.48.101 (BE/Belgium/Brussels Capital/Brussels/101.48.155.104.bc. ...
show more(ftpd) Failed FTP login from 104.155.48.101 (BE/Belgium/Brussels Capital/Brussels/101.48.155.104.bc.googleusercontent.com/[redacted])
show less
[AUTORAVALT][[05/10/2026 - 03:17:25 -03:00 UTC]
Attack from [Google LLC]
[104.155.48.101][101.48.155 ...
show more[AUTORAVALT][[05/10/2026 - 03:17:25 -03:00 UTC]
Attack from [Google LLC]
[104.155.48.101][101.48.155.104.bc.googleusercontent.com]
Action: BLocKed
FTP Brute-Force -> Running brute force credentials on the FTP server.
Brute-Force -> Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc.
]
...
show less
external host: 2026-10-05T07:42:27.133019+02:00 Erpelstolz postfix/smtpd[789903]: lost connection af ...
show moreexternal host: 2026-10-05T07:42:27.133019+02:00 Erpelstolz postfix/smtpd[789903]: lost connection after EHLO from 101.48.155.104.bc.googleusercontent.com[104.155.48.101]
2026-10-05T07:42:27.174070+02:00 Erpelstolz postfix/smtpd[789903]: improper command pipelining after CONNECT from 101.48.155.104.bc.googleusercontent.com[104.155.48.101]: HELP\r\n
2026-10-05T07:42:34.669112+02:00 Erpelstolz postfix/smtpd[789903]: lost connection after UNKNOWN from 101.48.155.104.bc.googleusercontent.com[104.155.48.101]
show less
Automated sensor: 24 telnet brute-force attempts over the last 24h (latest 2026-10-05T04:52Z). Usern ...
show moreAutomated sensor: 24 telnet brute-force attempts over the last 24h (latest 2026-10-05T04:52Z). Usernames tried: Call-ID: 50000, Contact: <sip:nm@nm>, From: <sip:nm@nm>;tag=root, GET / HTTP/1.0.
show less
Unsolicited TCP connection from 104.155.48.101 to port 0 at 2026-10-05T04:42:44Z. Source IP complete ...
show moreUnsolicited TCP connection from 104.155.48.101 to port 0 at 2026-10-05T04:42:44Z. Source IP completed three-way handshake to non-public service on this host. Detected by automated intrusion monitoring.
show less
2026-10-05T17:29:41.462219+13:00 eragon sm-mta[3611832]: 6954Teih3611832: 101.48.155.104.bc.googleus ...
show more2026-10-05T17:29:41.462219+13:00 eragon sm-mta[3611832]: 6954Teih3611832: 101.48.155.104.bc.googleusercontent.com [104.155.48.101] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
2026-10-05T17:29:45.514549+13:00 eragon sm-mta[3611844]: 6954TjgM3611844: rejecting commands from 101.48.155.104.bc.googleusercontent.com [104.155.48.101] due to pre-greeting traffic after 0 seconds
2026-10-05T17:29:47.543956+13:00 eragon sm-mta[3611851]: 6954TlOA3611851: rejecting commands from 101.48.155.104.bc.googleusercontent.com [104.155.48.101] due to pre-greeting traffic after 0 seconds
...
show less
2026-10-05T06:29:08.814492+02:00 mail postfix/postscreen[18803]: PREGREET 18 after 0.02 from [104.15 ...
show more2026-10-05T06:29:08.814492+02:00 mail postfix/postscreen[18803]: PREGREET 18 after 0.02 from [104.155.48.101]:55664: EHLO example.com\r\n
2026-10-05T06:29:14.434787+02:00 mail postfix/postscreen[18803]: HANGUP after 5.6 from [104.155.48.101]:55664 in tests after SMTP handshake
...
show less
Honeypot Finding: Telnet intrusion activity on TCP/23; successful login, command, or download activi ...
show moreHoneypot Finding: Telnet intrusion activity on TCP/23; successful login, command, or download activity observed.
show less