Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 114.248.15.249
This IP address has been reported a total of
62
times from
53 distinct
sources.
114.248.15.249 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 16
reports;
United States of America
with 10
reports;
France
with 7
reports.
The most common categories in these recent reports were:
Brute-Force
55
times;
SSH
55
times;
Port Scan
12
times;
Hacking
3
times;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-10-01T09:20:50.000734+02:00 slimbox sshd[584228]: Failed password for root from 114.248.15.249 ...
show more2026-10-01T09:20:50.000734+02:00 slimbox sshd[584228]: Failed password for root from 114.248.15.249 port 58652 ssh2
2026-10-01T09:20:52.152493+02:00 slimbox sshd[584230]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=114.248.15.249 user=root
2026-10-01T09:20:54.661664+02:00 slimbox sshd[584230]: Failed password for root from 114.248.15.249 port 58654 ssh2
...
show less
2026-10-01T07:23:47.984690+02:00 swsrv sshd[326940]: User root from 114.248.15.249 not allowed becau ...
show more2026-10-01T07:23:47.984690+02:00 swsrv sshd[326940]: User root from 114.248.15.249 not allowed because not listed in AllowUsers
2026-10-01T07:23:48.855309+02:00 swsrv sshd[326942]: User root from 114.248.15.249 not allowed because not listed in AllowUsers
2026-10-01T07:23:49.727410+02:00 swsrv sshd[326944]: User root from 114.248.15.249 not allowed because not listed in AllowUsers
2026-10-01T07:23:50.522844+02:00 swsrv sshd[326946]: User root from 114.248.15.249 not allowed because not listed in AllowUsers
...
show less
Repeated SSH password-authentication failures against an AceRDP management endpoint on TCP/22. OpenS ...
show moreRepeated SSH password-authentication failures against an AceRDP management endpoint on TCP/22. OpenSSH Failed password events triggered a 10-failure/600-second rule. Matched failures accumulated in this queued incident: 10. Detection time(s) UTC: 2026-10-01T04:50:25+00:00 to 2026-10-01T04:50:25+00:00. Source recorded by the receiving SSH service. Usernames and destination details omitted.
show less
Cowrie SSH brute-force activity detected. 2 or more observation(s) from 2026-09-30T21:05:19.000Z thr ...
show moreCowrie SSH brute-force activity detected. 2 or more observation(s) from 2026-09-30T21:05:19.000Z through 2026-09-30T21:05:19.000Z.
show less
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 114.248.15 ...
show moreWazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 114.248.15.249
show less
Port Scan
Brute-Force
SSH
Anonymous
Automated block on a production VoIP/web server: SSH authentication attempts on port 22/tcp after 5 ...
show moreAutomated block on a production VoIP/web server: SSH authentication attempts on port 22/tcp after 5 detected failures. Blocked automatically at the host.
show less
2026-09-30T13:37:01.345Z, an unauthorized SSH access attempt was detected from source IP address 114 ...
show more2026-09-30T13:37:01.345Z, an unauthorized SSH access attempt was detected from source IP address 114.248.15.249 by our NetFlow-based intrusion detection.
show less