This IP address has been reported a total of
878
times from
384 distinct
sources.
106.37.191.2 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-04-27T08:23:43.184948+03:00 main sshd-session[38281]: error: kex_exchange_identification: read: ...
show more2026-04-27T08:23:43.184948+03:00 main sshd-session[38281]: error: kex_exchange_identification: read: Connection reset by peer
2026-04-27T08:23:43.185032+03:00 main sshd-session[38281]: Connection reset by 106.37.191.2 port 46853
2026-04-27T08:24:05.958958+03:00 main sshd-session[39218]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.37.191.2 user=root
2026-04-27T08:24:07.731122+03:00 main sshd-session[39218]: Failed password for root from 106.37.191.2 port 56488 ssh2
2026-04-27T08:24:08.960947+03:00 main sshd-session[39218]: Disconnected from authenticating user root 106.37.191.2 port 56488 [preauth]
...
show less
Disconnected from authenticating user root 106.37.191.2 port 22687 [preauth]
Disconnected from authe ...
show moreDisconnected from authenticating user root 106.37.191.2 port 22687 [preauth]
Disconnected from authenticating user root 106.37.191.2 port 29408 [preauth]
Disconnected from authenticating user root 106.37.191.2 port 32940 [preauth]
Disconnected from authenticating user root 106.37.191.2 port 47086 [preauth]
Connection closed by 106.37.191.2 port 50742 [preauth]
show less
2026-04-26T06:02:45.167502+08:00 *hostname* sshd-session[46691]: Invalid user test1 from 106.37.191. ...
show more2026-04-26T06:02:45.167502+08:00 *hostname* sshd-session[46691]: Invalid user test1 from 106.37.191.2 port 13606
2026-04-26T06:03:57.817567+08:00 *hostname* sshd-session[46698]: Connection from 106.37.191.2 port 17509 on 10.0.4.13 port 22 rdomain ""
2026-04-26T06:03:59.261104+08:00 *hostname* sshd-session[46698]: Invalid user steam from 106.37.191.2 port 17509
2026-04-26T06:05:10.180456+08:00 *hostname* sshd-session[46709]: Connection from 106.37.191.2 port 21510 on 10.0.4.13 port 22 rdomain ""
2026-04-26T06:05:10.422309+08:00 *hostname* sshd-session[46709]: Invalid user ftpuser from 106.37.191.2 port 21510
show less
(sshd) Failed SSH login from 106.37.191.2 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction ...
show more(sshd) Failed SSH login from 106.37.191.2 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Apr 25 12:12:34 13419 sshd[12746]: Invalid user h from 106.37.191.2 port 41897
Apr 25 12:12:37 13419 sshd[12746]: Failed password for invalid user h from 106.37.191.2 port 41897 ssh2
Apr 25 12:31:52 13419 sshd[14513]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.37.191.2 user=root
Apr 25 12:31:54 13419 sshd[14513]: Failed password for root from 106.37.191.2 port 46895 ssh2
Apr 25 12:33:05 13419 sshd[14636]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.37.191.2 user=root
show less
2026-04-25T18:56:51.683769+08:00 *hostname* sshd-session[3597823]: Invalid user test from 106.37.191 ...
show more2026-04-25T18:56:51.683769+08:00 *hostname* sshd-session[3597823]: Invalid user test from 106.37.191.2 port 48198
2026-04-25T18:58:06.129670+08:00 *hostname* sshd-session[3597830]: Connection from 106.37.191.2 port 51856 on 10.66.0.230 port 22 rdomain ""
2026-04-25T18:58:07.761655+08:00 *hostname* sshd-session[3597830]: Invalid user ftpuser from 106.37.191.2 port 51856
2026-04-25T19:00:34.362219+08:00 *hostname* sshd-session[3597846]: Connection from 106.37.191.2 port 59415 on 10.66.0.230 port 22 rdomain ""
2026-04-25T19:00:34.662229+08:00 *hostname* sshd-session[3597846]: Invalid user ftpuser from 106.37.191.2 port 59415
show less
Brute-Force
SSH
Showing 811 to
825
of 878 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ