This IP address has been reported a total of
99
times from
75 distinct
sources.
104.248.239.230 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[BloumeGen Security] IP Access: 104.248.239.230. SSH brute-force login attempt. Target: Unknown. Pat ...
show more[BloumeGen Security] IP Access: 104.248.239.230. SSH brute-force login attempt. Target: Unknown. Paths: Multiple probes. Hits: 6
show less
Brute-Force
SSH
Anonymous
2026-06-12T21:41:08.512005 prodgateway sshd-session[45928]: Invalid user sol from 104.248.239.230 po ...
show more2026-06-12T21:41:08.512005 prodgateway sshd-session[45928]: Invalid user sol from 104.248.239.230 port 51396
2026-06-12T21:41:08.516446 prodgateway sshd-session[45928]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.248.239.230
2026-06-12T21:41:11.012074 prodgateway sshd-session[45928]: Failed password for invalid user sol from 104.248.239.230 port 51396 ssh2
...
show less
2026-06-12T21:43:26.120985+03:00 [HOSTNAME] sshd-session[322438]: Invalid user cstrike from 104.248. ...
show more2026-06-12T21:43:26.120985+03:00 [HOSTNAME] sshd-session[322438]: Invalid user cstrike from 104.248.239.230 port 59666
2026-06-12T21:45:01.193740+03:00 [HOSTNAME] sshd-session[322515]: Invalid user stage from 104.248.239.230 port 52842
2026-06-12T21:46:35.272758+03:00 [HOSTNAME] sshd-session[322586]: Invalid user applmgr from 104.248.239.230 port 47948
...
show less
Honeypot hit: Brute-force attack detected on 22/SSH
โข Credential used: root:123456AB
โข Number of log ...
show moreHoneypot hit: Brute-force attack detected on 22/SSH
โข Credential used: root:123456AB
โข Number of login attempts: 1
โข Client: SSH-2.0-libssh_0.9.6
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
2026-06-12T20:06:31.567580+02:00 [server] sshd-session[2771418]: Invalid user sambauser from 104.248 ...
show more2026-06-12T20:06:31.567580+02:00 [server] sshd-session[2771418]: Invalid user sambauser from 104.248.239.230 port 53226
2026-06-12T20:08:11.745966+02:00 [server] sshd-session[2771742]: Invalid user sftpuser from 104.248.239.230 port 52356
2026-06-12T20:09:43.644621+02:00 [server] sshd-session[2772131]: Invalid user james from 104.248.239.230 port 51230
...
show less
2026-06-12T18:06:10.673272+00:00 edge-obe-sto01.int.pdx.net.uk sshd[232138]: Invalid user sambauser ...
show more2026-06-12T18:06:10.673272+00:00 edge-obe-sto01.int.pdx.net.uk sshd[232138]: Invalid user sambauser from 104.248.239.230 port 60962
2026-06-12T18:07:50.921206+00:00 edge-obe-sto01.int.pdx.net.uk sshd[232248]: Invalid user sftpuser from 104.248.239.230 port 37550
2026-06-12T18:09:25.386115+00:00 edge-obe-sto01.int.pdx.net.uk sshd[232365]: Invalid user james from 104.248.239.230 port 53078
...
show less
[rede-164-29] (sshd) Failed SSH login from 104.248.239.230 (US/United States/-): 5 in the last 3600 ...
show more[rede-164-29] (sshd) Failed SSH login from 104.248.239.230 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jun 12 15:00:31 sshd[31077]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.248.239.230 user=[USERNAME]
Jun 12 15:00:33 sshd[31077]: Failed password for [USERNAME] from 104.248.239.230 port 41664 ssh2
Jun 12 15:06:17 sshd[31364]: Invalid user [USERNAME] from 104.248.239.230 port 37554
Jun 12 15:06:19 sshd[31364]: Failed password for invalid user [USERNAME] from 104.248.239.230 port 37554 ssh2
Jun 12 15:07:57 sshd[31415]: Invalid user [USERNAME] from
show less
Jun 12 16:58:49 n8n sshd[1122435]: Invalid user backend from 104.248.239.230 port 58484
Jun 12 17:07 ...
show moreJun 12 16:58:49 n8n sshd[1122435]: Invalid user backend from 104.248.239.230 port 58484
Jun 12 17:07:35 n8n sshd[1122490]: Invalid user deployuser from 104.248.239.230 port 48260
Jun 12 17:09:18 n8n sshd[1122517]: Invalid user lol from 104.248.239.230 port 38300
show less
2026-06-13T01:02:18.295331+08:00 vps-ebd448c1 sshd-session[4118351]: pam_unix(sshd:auth): authentica ...
show more2026-06-13T01:02:18.295331+08:00 vps-ebd448c1 sshd-session[4118351]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=104.248.239.230
2026-06-13T01:02:20.490263+08:00 vps-ebd448c1 sshd-session[4118351]: Failed password for invalid user backend from 104.248.239.230 port 35584 ssh2
2026-06-13T01:02:21.145259+08:00 vps-ebd448c1 sshd-session[4118351]: Disconnected from invalid user backend 104.248.239.230 port 35584 [preauth]
show less
2026-06-13T04:25:55.007038+12:00 localhost sshd[1942779]: Invalid user sara from 104.248.239.230 por ...
show more2026-06-13T04:25:55.007038+12:00 localhost sshd[1942779]: Invalid user sara from 104.248.239.230 port 46340
2026-06-13T04:28:01.696521+12:00 localhost sshd[1945188]: Invalid user shared from 104.248.239.230 port 46736
2026-06-13T04:34:02.758369+12:00 localhost sshd[1951099]: Invalid user marketing from 104.248.239.230 port 56332
2026-06-13T04:40:12.750402+12:00 localhost sshd[1957015]: Invalid user sinusbot from 104.248.239.230 port 41924
2026-06-13T04:48:17.584654+12:00 localhost sshd[1965220]: Invalid user verdaccio from 104.248.239.230 port 34808
show less
Brute-Force
SSH
Showing 1 to
15
of 99 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ