This IP address has been reported a total of
1,515
times from
668 distinct
sources.
104.243.42.167 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
May 21 23:02:06 b146-42 sshd[128463]: Invalid user android from 104.243.42.167 port 42352
May 21 23: ...
show moreMay 21 23:02:06 b146-42 sshd[128463]: Invalid user android from 104.243.42.167 port 42352
May 21 23:02:06 b146-42 sshd[128463]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167
May 21 23:02:09 b146-42 sshd[128463]: Failed password for invalid user android from 104.243.42.167 port 42352 ssh2
...
show less
2026-05-22T06:36:56.598410+02:00 proxy sshd[1695924]: Invalid user info from 104.243.42.167 port 485 ...
show more2026-05-22T06:36:56.598410+02:00 proxy sshd[1695924]: Invalid user info from 104.243.42.167 port 48508
2026-05-22T06:43:39.223339+02:00 proxy sshd[1696404]: Invalid user admin1 from 104.243.42.167 port 57476
...
show less
2026-05-22T04:01:09.483615+00:00 edge-drt-chi01.int.pdx.net.uk sshd[588546]: Invalid user user from ...
show more2026-05-22T04:01:09.483615+00:00 edge-drt-chi01.int.pdx.net.uk sshd[588546]: Invalid user user from 104.243.42.167 port 43548
2026-05-22T04:04:26.583078+00:00 edge-drt-chi01.int.pdx.net.uk sshd[588776]: Invalid user tejas from 104.243.42.167 port 50364
2026-05-22T04:07:47.183235+00:00 edge-drt-chi01.int.pdx.net.uk sshd[589031]: Invalid user arm from 104.243.42.167 port 43762
...
show less
2026-05-22T06:01:10.523863+02:00 proxy sshd[1692814]: Invalid user user from 104.243.42.167 port 363 ...
show more2026-05-22T06:01:10.523863+02:00 proxy sshd[1692814]: Invalid user user from 104.243.42.167 port 36336
2026-05-22T06:04:27.698625+02:00 proxy sshd[1693042]: Invalid user tejas from 104.243.42.167 port 44914
...
show less
Web App Attack
Anonymous
May 22 04:03:51 sftp-cognizant-chicago-1 sshd[1258675]: Invalid user user from 104.243.42.167 port 3 ...
show moreMay 22 04:03:51 sftp-cognizant-chicago-1 sshd[1258675]: Invalid user user from 104.243.42.167 port 39292
May 22 04:03:51 sftp-cognizant-chicago-1 sshd[1258675]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167
May 22 04:03:53 sftp-cognizant-chicago-1 sshd[1258675]: Failed password for invalid user user from 104.243.42.167 port 39292 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-05-22T05:32:11.776050 prodWEB sshd[26051]: Connection from 104.243.42.167 port 52620 on 46.105. ...
show more2026-05-22T05:32:11.776050 prodWEB sshd[26051]: Connection from 104.243.42.167 port 52620 on 46.105.46.67 port 22 rdomain ""
2026-05-22T05:32:12.390022 prodWEB sshd[26051]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167 user=root
2026-05-22T05:32:14.305172 prodWEB sshd[26051]: Failed password for root from 104.243.42.167 port 52620 ssh2
...
show less
2026-05-22T05:15:31.306481+02:00 amqp-host01.amqp.srvfarm.net sshd[51313]: Invalid user user12 from ...
show more2026-05-22T05:15:31.306481+02:00 amqp-host01.amqp.srvfarm.net sshd[51313]: Invalid user user12 from 104.243.42.167 port 51124
2026-05-22T05:15:31.411594+02:00 amqp-host01.amqp.srvfarm.net sshd[51313]: Disconnected from invalid user user12 104.243.42.167 port 51124 [preauth]
2026-05-22T05:18:52.412029+02:00 amqp-host01.amqp.srvfarm.net sshd[51431]: Disconnected from authenticating user root 104.243.42.167 port 36788 [preauth]
2026-05-22T05:22:10.998330+02:00 amqp-host01.amqp.srvfarm.net sshd[51601]: Invalid user ts3 from 104.243.42.167 port 35438
2026-05-22T05:22:11.189194+02:00 amqp-host01.amqp.srvfarm.net sshd[51601]: Disconnected from invalid user ts3 104.243.42.167 port 35438 [preauth]
show less
104.243.42.167 (US/United States/-), 5 distributed sshd attacks on account [root] in the last 3600 s ...
show more104.243.42.167 (US/United States/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: May 21 22:20:06 14725 sshd[4511]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167 user=root
May 21 21:40:37 14725 sshd[32306]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.29.76.173 user=root
May 21 21:40:39 14725 sshd[32306]: Failed password for root from 154.29.76.173 port 54830 ssh2
May 21 22:11:06 14725 sshd[3181]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167 user=root
May 21 22:11:08 14725 sshd[3181]: Failed password for root from 104.243.42.167 port 36388 ssh2
IP Addresses Blocked:
show less
Brute-Force
SSH
Anonymous
2026-05-22T05:15:57.661391 prodWEB sshd[25795]: Invalid user user12 from 104.243.42.167 port 55660
2 ...
show more2026-05-22T05:15:57.661391 prodWEB sshd[25795]: Invalid user user12 from 104.243.42.167 port 55660
2026-05-22T05:15:57.665153 prodWEB sshd[25795]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167
2026-05-22T05:15:59.732312 prodWEB sshd[25795]: Failed password for invalid user user12 from 104.243.42.167 port 55660 ssh2
...
show less
2026-05-22T05:15:53.000029+02:00 jane sshd-session[3949156]: Invalid user user12 from 104.243.42.167 ...
show more2026-05-22T05:15:53.000029+02:00 jane sshd-session[3949156]: Invalid user user12 from 104.243.42.167 port 46062
2026-05-22T05:15:53.002095+02:00 jane sshd-session[3949156]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.243.42.167
2026-05-22T05:15:54.768801+02:00 jane sshd-session[3949156]: Failed password for invalid user user12 from 104.243.42.167 port 46062 ssh2
...
show less
2026-05-21T23:13:26.212782-04:00 hun sshd[114042]: Failed password for root from 104.243.42.167 port ...
show more2026-05-21T23:13:26.212782-04:00 hun sshd[114042]: Failed password for root from 104.243.42.167 port 38776 ssh2
2026-05-21T23:13:26.668078-04:00 hun sshd[114042]: Disconnected from authenticating user root 104.243.42.167 port 38776 [preauth]
...
show less
May 22 04:43:10 webhosting05 sshd[2046041]: Invalid user dokku from 104.243.42.167 port 46310
May 22 ...
show moreMay 22 04:43:10 webhosting05 sshd[2046041]: Invalid user dokku from 104.243.42.167 port 46310
May 22 04:46:18 webhosting05 sshd[2046466]: Invalid user fff from 104.243.42.167 port 38750
May 22 04:46:18 webhosting05 sshd[2046466]: Invalid user fff from 104.243.42.167 port 38750
...
show less
Brute-Force
SSH
Showing 1471 to
1485
of 1515 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ