This IP address has been reported a total of
1,428
times from
585 distinct
sources.
118.145.104.105 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-02T00:26:07.128136+02:00 localhost sshd[158170]: Invalid user orangepi from 118.145.104.105 ...
show more2026-06-02T00:26:07.128136+02:00 localhost sshd[158170]: Invalid user orangepi from 118.145.104.105 port 46186
2026-06-02T00:26:07.135744+02:00 localhost sshd[158170]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=118.145.104.105
2026-06-02T00:26:09.559962+02:00 localhost sshd[158170]: Failed password for invalid user orangepi from 118.145.104.105 port 46186 ssh2
2026-06-02T00:26:46.517636+02:00 localhost sshd[158356]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=118.145.104.105 user=root
2026-06-02T00:26:48.294060+02:00 localhost sshd[158356]: Failed password for root from 118.145.104.105 port 58358 ssh2
...
show less
(sshd) Failed SSH login from 118.145.104.105 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direct ...
show more(sshd) Failed SSH login from 118.145.104.105 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 1 17:09:52 18113 sshd[20810]: Invalid user admin from 118.145.104.105 port 47768
Jun 1 17:09:54 18113 sshd[20810]: Failed password for invalid user admin from 118.145.104.105 port 47768 ssh2
Jun 1 17:10:35 18113 sshd[21244]: Invalid user orangepi from 118.145.104.105 port 50252
Jun 1 17:10:36 18113 sshd[21244]: Failed password for invalid user orangepi from 118.145.104.105 port 50252 ssh2
Jun 1 17:11:15 18113 sshd[21703]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=118.145.104.105 user=root
show less
Jun 1 22:08:10 dabeau sshd[25497]: Invalid user admin from 118.145.104.105 port 60368
Jun 1 22:08: ...
show moreJun 1 22:08:10 dabeau sshd[25497]: Invalid user admin from 118.145.104.105 port 60368
Jun 1 22:08:10 dabeau sshd[25497]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=118.145.104.105
Jun 1 22:08:11 dabeau sshd[25497]: Failed password for invalid user admin from 118.145.104.105 port 60368 ssh2
...
show less
2026-06-01T23:51:04.551116+02:00 server sshd[2705190]: Invalid user admin from 118.145.104.105 port ...
show more2026-06-01T23:51:04.551116+02:00 server sshd[2705190]: Invalid user admin from 118.145.104.105 port 50872
2026-06-01T23:51:38.851911+02:00 server sshd[2705339]: Invalid user orangepi from 118.145.104.105 port 42892
2026-06-01T23:52:14.260177+02:00 server sshd[2705414]: User root from 118.145.104.105 not allowed because listed in DenyUsers
2026-06-01T23:53:04.757272+02:00 server sshd[2705532]: User root from 118.145.104.105 not allowed because listed in DenyUsers
2026-06-01T23:53:45.843402+02:00 server sshd[2705646]: User root from 118.145.104.105 not allowed because listed in DenyUsers
...
show less
Client sent invalid (non-HTTP) message to honeypot web server:
118.145.104.105 - - [01/Jun/2026:14:3 ...
show moreClient sent invalid (non-HTTP) message to honeypot web server:
118.145.104.105 - - [01/Jun/2026:14:30:52 -0500] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-" "-" ""
show less
Port Scan on Honeypot | Ports: 2222/SSH-alt(2x) | Proto: TCP(2) | Flags: all SYN | TTL: 43 | Len: 40 ...
show morePort Scan on Honeypot | Ports: 2222/SSH-alt(2x) | Proto: TCP(2) | Flags: all SYN | TTL: 43 | Len: 40B(2x) | Win: 65535(2) | F2B/ufw-honeypot@2026-06-01T15:16:55Z
show less
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET WEB_SERVER /bin ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt). Ip 118.145.104.105 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-06-01 15:15:13.632860783 +0000 UTC
show less
Unauthorized network connection attempt(s) via TCP/UDP port(s) from TI-mapped IP entity detected [Fo ...
show moreUnauthorized network connection attempt(s) via TCP/UDP port(s) from TI-mapped IP entity detected [Fortinet/Sentinel].
show less
Port Scan
Showing 76 to
90
of 1428 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ