This IP address has been reported a total of
1,009
times from
426 distinct
sources.
106.75.29.99 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-01T07:09:02.770650+03:00 kotia sshd-session[199654]: Invalid user rocky from 106.75.29.99 po ...
show more2026-06-01T07:09:02.770650+03:00 kotia sshd-session[199654]: Invalid user rocky from 106.75.29.99 port 54206
...
show less
Jun 1 05:26:05 wh02 sshd[590798]: Received disconnect from 106.75.29.99 port 56514:11: Bye Bye [pre ...
show moreJun 1 05:26:05 wh02 sshd[590798]: Received disconnect from 106.75.29.99 port 56514:11: Bye Bye [preauth]
Jun 1 05:26:05 wh02 sshd[590798]: Disconnected from authenticating user root 106.75.29.99 port 56514 [preauth]
Jun 1 05:34:36 wh02 sshd[603519]: Received disconnect from 106.75.29.99 port 49946:11: Bye Bye [preauth]
Jun 1 05:34:36 wh02 sshd[603519]: Disconnected from authenticating user root 106.75.29.99 port 49946 [preauth]
Jun 1 05:36:34 wh02 sshd[604548]: Invalid user odoo from 106.75.29.99 port 48686
Jun 1 05:36:34 wh02 sshd[604548]: Received disconnect from 106.75.29.99 port 48686:11: Bye Bye [preauth]
Jun 1 05:36:34 wh02 sshd[604548]: Disconnected from invalid user odoo 106.75.29.99 port 48686 [preauth]
Jun 1 05:38:42 wh02 sshd[606562]: Received disconnect from 106.75.29.99 port 46296:11: Bye Bye [preauth]
Jun 1 05:38:42 wh02 sshd[606562]: Disconnected from authenticating user root 106.75.29.99 port 46296 [preauth]
Jun 1 05:40:33 wh02 sshd[607506]: Invalid user rock
show less
Cowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-01T03:27:47Z and 2026-06-0 ...
show moreCowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-01T03:27:47Z and 2026-06-01T04:04:38Z
show less
Brute-Force
SSH
Anonymous
2026-06-01T12:37:18.180486+09:00 kabedon sshd[1854801]: Invalid user odoo from 106.75.29.99 port 400 ...
show more2026-06-01T12:37:18.180486+09:00 kabedon sshd[1854801]: Invalid user odoo from 106.75.29.99 port 40034
2026-06-01T12:37:18.183241+09:00 kabedon sshd[1854801]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99
2026-06-01T12:37:19.928448+09:00 kabedon sshd[1854801]: Failed password for invalid user odoo from 106.75.29.99 port 40034 ssh2
2026-06-01T12:39:23.883940+09:00 kabedon sshd[1856525]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99 user=root
2026-06-01T12:39:25.789806+09:00 kabedon sshd[1856525]: Failed password for root from 106.75.29.99 port 52182 ssh2
...
show less
Jun 1 02:33:31 flashfire sshd[2157730]: Disconnected from authenticating user root 106.75.29.99 por ...
show moreJun 1 02:33:31 flashfire sshd[2157730]: Disconnected from authenticating user root 106.75.29.99 port 55860 [preauth]
Jun 1 02:43:49 flashfire sshd[2163433]: Invalid user tony from 106.75.29.99 port 38670
Jun 1 02:43:49 flashfire sshd[2163433]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99
Jun 1 02:43:52 flashfire sshd[2163433]: Failed password for invalid user tony from 106.75.29.99 port 38670 ssh2
Jun 1 02:43:53 flashfire sshd[2163433]: Disconnected from invalid user tony 106.75.29.99 port 38670 [preauth]
...
show less
May 31 21:13:09 106.75.29.99 TCP SPT=41810 DPT=222 SYN
May 31 21:13:10 106.75.29.99 TCP SPT=41810 DP ...
show moreMay 31 21:13:09 106.75.29.99 TCP SPT=41810 DPT=222 SYN
May 31 21:13:10 106.75.29.99 TCP SPT=41810 DPT=222 SYN
May 31 21:13:11 106.75.29.99 TCP SPT=41810 DPT=222 SYN
...
show less
2026-06-01T01:14:42.858039+02:00 domotica sshd-session[14862]: Invalid user tester from 106.75.29.99 ...
show more2026-06-01T01:14:42.858039+02:00 domotica sshd-session[14862]: Invalid user tester from 106.75.29.99 port 40110
...
show less
106.75.29.99 (CN/China/qrdwrvh.cn), 5 distributed sshd attacks on account [root] in the last 3600 se ...
show more106.75.29.99 (CN/China/qrdwrvh.cn), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: May 31 16:36:17 14815 sshd[24121]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99 user=root
May 31 16:28:07 14815 sshd[19821]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=175.182.39.145 user=root
May 31 16:28:09 14815 sshd[19821]: Failed password for root from 175.182.39.145 port 34132 ssh2
May 31 16:22:51 14815 sshd[16754]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99 user=root
May 31 16:22:54 14815 sshd[16754]: Failed password for root from 106.75.29.99 port 59822 ssh2
IP Addresses Blocked:
show less
Report 2419620 with IP 3343176 for SSH brute-force attack by source 3438450 via ssh-honeypot/0.2.0+h ...
show moreReport 2419620 with IP 3343176 for SSH brute-force attack by source 3438450 via ssh-honeypot/0.2.0+http
show less
(sshd) Failed SSH login from 106.75.29.99 (CN/China/ygmfoce.cn): 5 in the last 3600 secs; Ports: *; ...
show more(sshd) Failed SSH login from 106.75.29.99 (CN/China/ygmfoce.cn): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 31 14:10:21 17453 sshd[17457]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=106.75.29.99 user=root
May 31 14:10:23 17453 sshd[17457]: Failed password for root from 106.75.29.99 port 59130 ssh2
May 31 14:14:19 17453 sshd[19275]: Invalid user erpuser from 106.75.29.99 port 51024
May 31 14:14:21 17453 sshd[19275]: Failed password for invalid user erpuser from 106.75.29.99 port 51024 ssh2
May 31 14:15:48 17453 sshd[19892]: Invalid user admin from 106.75.29.99 port 59194
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
Brute-Force
SSH
Showing 46 to
60
of 1009 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ