This IP address has been reported a total of
132
times from
115 distinct
sources.
104.199.47.35 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Repeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed ...
show moreRepeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed authentication attempts from this IP across an extended period.
show less
This IP address carried out 4 port scanning attempts on 01-06-2026. For more information or to repor ...
show moreThis IP address carried out 4 port scanning attempts on 01-06-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
TSEC Honeypot Network report. Threat score: 100/100. Categories: Port Scan, Hacking, Brute-Force, We ...
show moreTSEC Honeypot Network report. Threat score: 100/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: cowrie, ssh-telnet. Context: IP observed in Suricata network metadata.
show less
2026-06-01T08:04:32.588383+00:00 boron sshd[123773]: pam_unix(sshd:auth): authentication failure; lo ...
show more2026-06-01T08:04:32.588383+00:00 boron sshd[123773]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.199.47.35
2026-06-01T08:04:34.521918+00:00 boron sshd[123773]: Failed password for invalid user admin from 104.199.47.35 port 23064 ssh2
2026-06-01T08:04:35.942933+00:00 boron sshd[123773]: Connection closed by invalid user admin 104.199.47.35 port 23064 [preauth]
...
show less
2026-06-01T10:00:00.956625+02:00 server sshd-session[6530]: Invalid user admin from 104.199.47.35 po ...
show more2026-06-01T10:00:00.956625+02:00 server sshd-session[6530]: Invalid user admin from 104.199.47.35 port 51066
...
show less
Jun 1 07:58:42 fail2ban sshd[3667517]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJun 1 07:58:42 fail2ban sshd[3667517]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.199.47.35
Jun 1 07:58:45 fail2ban sshd[3667517]: Failed password for invalid user admin from 104.199.47.35 port 18282 ssh2
...
show less
2026-06-01T09:17:28.722038+02:00 gw-de37-01.guestgw.net sshd[686371]: Connection closed by 104.199.4 ...
show more2026-06-01T09:17:28.722038+02:00 gw-de37-01.guestgw.net sshd[686371]: Connection closed by 104.199.47.35 port 22628
2026-06-01T09:17:36.304471+02:00 gw-de37-01.guestgw.net sshd[686398]: Unable to negotiate with 104.199.47.35 port 37026: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1 [preauth]
2026-06-01T09:17:40.657254+02:00 gw-de37-01.guestgw.net sshd[686415]: Unable to negotiate with 104.199.47.35 port 37038: no matching host key type found. Their offer: ssh-dss [preauth]
2026-06-01T09:17:40.977594+02:00 gw-de37-01.guestgw.net sshd[686417]: Unable to negotiate with 104.199.47.35 port 37052: no matching host key type found. Their offer: ssh-rsa [preauth]
2026-06-01T09:17:41.293251+02:00 gw-de37-01.guestgw.net sshd[686421]: Unable to negotiate with 104.199.47.35 port 37056: no matching MAC found. Their offer: hmac-md5,hmac-sha1,hmac-ripemd160 [preauth]
show less
Brute-Force
Showing 1 to
15
of 132 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ