This IP address has been reported a total of
3,703
times from
1,061 distinct
sources.
107.150.103.12 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Apr 16 14:28:22 LU-VPS01 sshd[1093]: pam_unix(sshd:auth): authentication failure; logname= uid=0 eui ...
show moreApr 16 14:28:22 LU-VPS01 sshd[1093]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12
Apr 16 14:28:24 LU-VPS01 sshd[1093]: Failed password for invalid user user from 107.150.103.12 port 49144 ssh2
Apr 16 14:32:41 LU-VPS01 sshd[1240]: Failed password for root from 107.150.103.12 port 47894 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-04-16T21:17:04.182524+00:00 s158416 sshd[1305781]: Failed password for www-data from 107.150.10 ...
show more2026-04-16T21:17:04.182524+00:00 s158416 sshd[1305781]: Failed password for www-data from 107.150.103.12 port 56244 ssh2
2026-04-16T21:18:36.282808+00:00 s158416 sshd[1305845]: Invalid user ubuntu from 107.150.103.12 port 48650
2026-04-16T21:18:36.289860+00:00 s158416 sshd[1305845]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12
2026-04-16T21:18:39.015282+00:00 s158416 sshd[1305845]: Failed password for invalid user ubuntu from 107.150.103.12 port 48650 ssh2
2026-04-16T21:20:12.522287+00:00 s158416 sshd[1305970]: Invalid user user20 from 107.150.103.12 port 54786
...
show less
Credential enumeration: 3 login attempts w/ usernames 345gs5662d34, admin + dictionary passwords. SS ...
show moreCredential enumeration: 3 login attempts w/ usernames 345gs5662d34, admin + dictionary passwords. SSH client libssh 0.11.1. Session duration 5sec across 3 connections = rapid-fire attempts. Two cmd chains executed: (1) SSH key injectionโremoves .ssh dir, recreates, echoes 2048-bit RSA pubkey to authorized_keys for persistence; (2) File attribute manipulation (chattr -ia, lockr -ia) to prevent deletion/detection of planted SSH creds. Cred set admin/admin20! = weak pattern. libssh_0.11.1 suggests automated framework. No malware, dlz, secondary tools observed. Attack = brute-force + SSH key backdoor for persistent remote access. Prioritizes persistence over lateral movement/exfil.
show less
Brute-Force
SSH
Anonymous
2026-04-16T20:48:16.666386+00:00 gra11-01-secure sshd[111526]: Invalid user admin from 107.150.103.1 ...
show more2026-04-16T20:48:16.666386+00:00 gra11-01-secure sshd[111526]: Invalid user admin from 107.150.103.12 port 45484
2026-04-16T20:52:21.280990+00:00 gra11-01-secure sshd[111534]: Invalid user nsuser from 107.150.103.12 port 40748
2026-04-16T20:55:30.694390+00:00 gra11-01-secure sshd[111543]: Invalid user web from 107.150.103.12 port 53312
...
show less
2026-04-16T21:48:24.809459+01:00 websrv sshd[2793301]: Failed password for invalid user admin from 1 ...
show more2026-04-16T21:48:24.809459+01:00 websrv sshd[2793301]: Failed password for invalid user admin from 107.150.103.12 port 36244 ssh2
2026-04-16T21:50:48.930765+01:00 websrv sshd[2793421]: Invalid user ubuntu from 107.150.103.12 port 40680
2026-04-16T21:50:48.941090+01:00 websrv sshd[2793421]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12
2026-04-16T21:50:51.011343+01:00 websrv sshd[2793421]: Failed password for invalid user ubuntu from 107.150.103.12 port 40680 ssh2
2026-04-16T21:52:23.097435+01:00 websrv sshd[2793490]: Invalid user nsuser from 107.150.103.12 port 55214
...
show less
Brute-Force
SSH
Anonymous
2026-04-16T20:45:11.210356+00:00 de-fra2-unifi1 sshd[4016474]: Invalid user admin from 107.150.103.1 ...
show more2026-04-16T20:45:11.210356+00:00 de-fra2-unifi1 sshd[4016474]: Invalid user admin from 107.150.103.12 port 42962
2026-04-16T20:49:51.828637+00:00 de-fra2-unifi1 sshd[4016524]: Invalid user ubuntu from 107.150.103.12 port 35172
2026-04-16T20:51:25.272647+00:00 de-fra2-unifi1 sshd[4016534]: Invalid user nsuser from 107.150.103.12 port 52082
...
show less
Brute-Force
SSH
Anonymous
2026-04-16T20:44:57.644416+00:00 s158416 sshd[1303627]: Failed password for invalid user admin from ...
show more2026-04-16T20:44:57.644416+00:00 s158416 sshd[1303627]: Failed password for invalid user admin from 107.150.103.12 port 48364 ssh2
2026-04-16T20:49:46.671588+00:00 s158416 sshd[1303942]: Invalid user ubuntu from 107.150.103.12 port 32780
2026-04-16T20:49:46.678503+00:00 s158416 sshd[1303942]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12
2026-04-16T20:49:48.572521+00:00 s158416 sshd[1303942]: Failed password for invalid user ubuntu from 107.150.103.12 port 32780 ssh2
2026-04-16T20:51:20.937076+00:00 s158416 sshd[1304074]: Invalid user nsuser from 107.150.103.12 port 44348
...
show less
2026-04-16T21:02:19.603005+01:00 sshd-session[3894024]: Disconnected from authenticating user root ...
show more2026-04-16T21:02:19.603005+01:00 sshd-session[3894024]: Disconnected from authenticating user root 107.150.103.12 port 47472 [preauth]
2026-04-16T21:07:09.667783+01:00 sshd-session[3947838]: Invalid user admin from 107.150.103.12 port 54462
2026-04-16T21:07:09.860162+01:00 sshd-session[3947838]: Disconnected from invalid user admin 107.150.103.12 port 54462 [preauth]
...
show less
2026-04-17T02:22:55.213014 mail.atmatech.id sshd[1790419]: pam_unix(sshd:auth): authentication failu ...
show more2026-04-17T02:22:55.213014 mail.atmatech.id sshd[1790419]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12
2026-04-17T02:22:57.393371 mail.atmatech.id sshd[1790419]: Failed password for invalid user ubuntu from 107.150.103.12 port 39662 ssh2
2026-04-17T02:26:01.306964 mail.atmatech.id sshd[1793404]: Invalid user usuario2 from 107.150.103.12 port 51950
...
show less
2026-04-16T20:51:05.786649+02:00 vps-80784d41 sshd-session[2638132]: pam_unix(sshd:auth): authentica ...
show more2026-04-16T20:51:05.786649+02:00 vps-80784d41 sshd-session[2638132]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=107.150.103.12 user=teamspeak
2026-04-16T20:51:07.756867+02:00 vps-80784d41 sshd-session[2638132]: Failed password for teamspeak from 107.150.103.12 port 38890 ssh2
2026-04-16T20:52:37.165877+02:00 vps-80784d41 sshd-session[2638284]: Invalid user yangy from 107.150.103.12 port 45184
...
show less
Brute-Force
SSH
Showing 3676 to
3690
of 3703 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ