This IP address has been reported a total of
35
times from
33 distinct
sources.
119.41.148.245 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-10T15:05:17.721488+00:00 vultr sshd[2984449]: Invalid user rdc from 119.41.148.245 port 4107 ...
show more2026-06-10T15:05:17.721488+00:00 vultr sshd[2984449]: Invalid user rdc from 119.41.148.245 port 41076
2026-06-10T15:05:17.725592+00:00 vultr sshd[2984449]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.41.148.245
2026-06-10T15:05:19.626686+00:00 vultr sshd[2984449]: Failed password for invalid user rdc from 119.41.148.245 port 41076 ssh2
2026-06-10T15:08:10.190365+00:00 vultr sshd[2986867]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.41.148.245 user=syslog
2026-06-10T15:08:12.176515+00:00 vultr sshd[2986867]: Failed password for syslog from 119.41.148.245 port 40026 ssh2
...
show less
Jun 10 12:02:15 ice1 sshd[3920351]: Invalid user qqqq from 119.41.148.245 port 57592
Jun 10 12:38:57 ...
show moreJun 10 12:02:15 ice1 sshd[3920351]: Invalid user qqqq from 119.41.148.245 port 57592
Jun 10 12:38:57 ice1 sshd[3920693]: Invalid user foo from 119.41.148.245 port 42588
...
show less
2026-06-10T10:33:30.566439+00:00 oxyde-protect-server sshd-session[19030]: Failed password for root ...
show more2026-06-10T10:33:30.566439+00:00 oxyde-protect-server sshd-session[19030]: Failed password for root from 119.41.148.245 port 55126 ssh2
2026-06-10T10:34:46.186118+00:00 oxyde-protect-server sshd-session[19043]: Invalid user kt from 119.41.148.245 port 41070
2026-06-10T10:34:46.189096+00:00 oxyde-protect-server sshd-session[19043]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.41.148.245
2026-06-10T10:34:48.134774+00:00 oxyde-protect-server sshd-session[19043]: Failed password for invalid user kt from 119.41.148.245 port 41070 ssh2
2026-06-10T10:36:05.358477+00:00 oxyde-protect-server sshd-session[19058]: Invalid user serv from 119.41.148.245 port 55242
...
show less
Jun 10 04:09:14 au-mirror sshd[1104611]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJun 10 04:09:14 au-mirror sshd[1104611]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.41.148.245
Jun 10 04:09:16 au-mirror sshd[1104611]: Failed password for invalid user pacs from 119.41.148.245 port 46630 ssh2
...
show less
119.41.148.245 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale ...
show more119.41.148.245 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale industrial operation attempting unrelenting brute-force login attempts for months on end - between all CIDR ranges in the botnet, our servers receive over 800 authentication attempts per minute on smtp, imap and relative mail ports, as well as ssh, and other protocols.
IP INFO:
- IP 119.41.148.245
- Anycast false
- City N/A
- Region N/A
- Region Code N/A
- Country N/A (N/A)
- Continent N/A (N/A)
- Range N/A
- Provider N/A
- Organisation N/A
- Proxy N/A
- Type N/A
show less
2026-06-10T00:56:36.228378+01:00 vps sshd[1153266]: pam_unix(sshd:auth): authentication failure; log ...
show more2026-06-10T00:56:36.228378+01:00 vps sshd[1153266]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.41.148.245 user=root
2026-06-10T00:56:38.346813+01:00 vps sshd[1153266]: Failed password for invalid user root from 119.41.148.245 port 41154 ssh2
2026-06-10T01:11:27.312435+01:00 vps sshd[1172464]: User root from 119.41.148.245 not allowed because not listed in AllowUsers
...
show less
SSH honeypot interaction detected. The source host initiated a connection to a monitored SSH endpoin ...
show moreSSH honeypot interaction detected. The source host initiated a connection to a monitored SSH endpoint, behavior consistent with automated SSH scanning or brute-force reconnaissance.
show less
Brute-Force
SSH
Showing 1 to
15
of 35 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ