This IP address has been reported a total of
60
times from
46 distinct
sources.
113.195.248.6 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
(sshd) Failed SSH login from 113.195.248.6 (CN/China/6.248.195.113.adsl-pool.jx.chinaunicom.com): 5 ...
show more(sshd) Failed SSH login from 113.195.248.6 (CN/China/6.248.195.113.adsl-pool.jx.chinaunicom.com): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 12 11:46:32 13817 sshd[7108]: Did not receive identification string from 113.195.248.6 port 59170
Jun 12 11:46:33 13817 sshd[7110]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 12 11:46:35 13817 sshd[7110]: Failed password for root from 113.195.248.6 port 59184 ssh2
Jun 12 11:46:36 13817 sshd[7162]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 12 11:46:38 13817 sshd[7162]: Failed password for root from 113.195.248.6 port 59196 ssh2
show less
Honeypot [fra-de-honeypot]: Empty payload (likely service probe); 22220 [1] TCP
Reported by DisPaisy ...
show moreHoneypot [fra-de-honeypot]: Empty payload (likely service probe); 22220 [1] TCP
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
2026-06-11T13:30:03.051406+00:00 sshd[63241]: Failed password for root from 113.195.248.6 port 4314 ...
show more2026-06-11T13:30:03.051406+00:00 sshd[63241]: Failed password for root from 113.195.248.6 port 43142 ssh2
...
show less
2026-06-11T10:46:55.854337+02:00 server sshd-session[29928]: Connection closed by 113.195.248.6 port ...
show more2026-06-11T10:46:55.854337+02:00 server sshd-session[29928]: Connection closed by 113.195.248.6 port 55550 [preauth]
...
show less
Honeypot [uk-production01]: Brute-force attack detected on 22/SSH
โข Credentials: root:๏ปฟ------fuck--- ...
show moreHoneypot [uk-production01]: Brute-force attack detected on 22/SSH
โข Credentials: root:๏ปฟ------fuck------, root:root123456
โข Number of login attempts: 2
โข 1 command(s) were executed during the session
โข Client: SSH-2.0-Go
show less
(sshd) Failed SSH login from 113.195.248.6 (CN/China/6.248.195.113.adsl-pool.jx.chinaunicom.com): 5 ...
show more(sshd) Failed SSH login from 113.195.248.6 (CN/China/6.248.195.113.adsl-pool.jx.chinaunicom.com): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 10 17:56:42 15084 sshd[10121]: Did not receive identification string from 113.195.248.6 port 36552
Jun 10 17:56:53 15084 sshd[10122]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 10 17:56:55 15084 sshd[10122]: Failed password for root from 113.195.248.6 port 36558 ssh2
Jun 10 17:56:57 15084 sshd[10223]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 10 17:56:59 15084 sshd[10223]: Failed password for root from 113.195.248.6 port 34024 ssh2
show less
Jun 10 20:23:33 vmi174663 sshd[2532802]: Failed password for root from 113.195.248.6 port 54122 ssh2 ...
show moreJun 10 20:23:33 vmi174663 sshd[2532802]: Failed password for root from 113.195.248.6 port 54122 ssh2
Jun 10 20:23:35 vmi174663 sshd[2532804]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 10 20:23:37 vmi174663 sshd[2532804]: Failed password for root from 113.195.248.6 port 59554 ssh2
Jun 10 20:23:39 vmi174663 sshd[2532826]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.248.6 user=root
Jun 10 20:23:41 vmi174663 sshd[2532826]: Failed password for root from 113.195.248.6 port 59558 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 60 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ