This IP address has been reported a total of
14
times from
13 distinct
sources.
121.11.238.49 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-07-18T04:15:13.385339+02:00 ns3124905 sshd-session[1056886]: Failed password for root from 121. ...
show more2026-07-18T04:15:13.385339+02:00 ns3124905 sshd-session[1056886]: Failed password for root from 121.11.238.49 port 58294 ssh2
2026-07-18T04:17:19.163102+02:00 ns3124905 sshd-session[1057585]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T04:17:20.781402+02:00 ns3124905 sshd-session[1057585]: Failed password for root from 121.11.238.49 port 52492 ssh2
...
show less
2026-07-17T22:18:48.587817 arp-hbs-db sshd[1896809]: Failed password for root from 121.11.238.49 por ...
show more2026-07-17T22:18:48.587817 arp-hbs-db sshd[1896809]: Failed password for root from 121.11.238.49 port 39424 ssh2
2026-07-17T22:18:51.461035 arp-hbs-db sshd[1897122]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-17T22:18:53.578271 arp-hbs-db sshd[1897122]: Failed password for root from 121.11.238.49 port 56922 ssh2
...
show less
2026-07-18T01:32:24.134194+02:00 dArtagnan sshd[4064505]: Failed password for root from 121.11.238.4 ...
show more2026-07-18T01:32:24.134194+02:00 dArtagnan sshd[4064505]: Failed password for root from 121.11.238.49 port 56660 ssh2
2026-07-18T01:32:26.106268+02:00 dArtagnan sshd[4064543]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T01:32:27.676495+02:00 dArtagnan sshd[4064543]: Failed password for root from 121.11.238.49 port 45130 ssh2
...
show less
2026-07-18T01:17:23.981422webmail sshd[479054]: Failed password for root from 121.11.238.49 port 475 ...
show more2026-07-18T01:17:23.981422webmail sshd[479054]: Failed password for root from 121.11.238.49 port 47540 ssh2
2026-07-18T01:17:26.829022webmail sshd[479056]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T01:17:28.841818webmail sshd[479056]: Failed password for root from 121.11.238.49 port 39314 ssh2
2026-07-18T01:17:31.259327webmail sshd[479058]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T01:17:33.628055webmail sshd[479058]: Failed password for root from 121.11.238.49 port 57854 ssh2
...
show less
(sshd) Failed SSH login from 121.11.238.49 (CN/China/-): 5 in the last 3600 secs; Ports: *; Directio ...
show more(sshd) Failed SSH login from 121.11.238.49 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: Jul 17 23:48:07 da057 sshd[3418492]: Invalid user user from 121.11.238.49 port 46256
Jul 17 23:48:09 da057 sshd[3418511]: Invalid user user from 121.11.238.49 port 52462
Jul 17 23:48:10 da057 sshd[3418538]: Invalid user user from 121.11.238.49 port 57882
Jul 17 23:48:11 da057 sshd[3418569]: Invalid user user from 121.11.238.49 port 36252
Jul 17 23:50:14 da057 sshd[3422465]: Invalid user user from 121.11.238.49 port 43118
show less
SSH brute force attempt using Go-based SSH client. Single credential pair tested: root/---fuck_you-- ...
show moreSSH brute force attempt using Go-based SSH client. Single credential pair tested: root/---fuck_you----. Post-authentication, attacker executed uname -s -m to enumerate system architecture. No malware downloads, persistence mechanisms, or lateral movement observed. Attack duration approximately 4 seconds across 2 sessions. Credential appears intentionally obfuscated rather than dictionary-based. Go SSH client suggests automated scanning framework rather than manual interaction. No data exfiltration or shell access maintained. Standard reconnaissance-only behavior typical of automated vulnerability assessment or botnet scanning activity.
show less
2026-07-18T03:53:54.011026oswald-lab sshd[3793533]: Failed password for root from 121.11.238.49 port ...
show more2026-07-18T03:53:54.011026oswald-lab sshd[3793533]: Failed password for root from 121.11.238.49 port 42022 ssh2
2026-07-18T03:53:57.456674oswald-lab sshd[3793556]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T03:53:59.390289oswald-lab sshd[3793556]: Failed password for root from 121.11.238.49 port 35352 ssh2
2026-07-18T03:54:02.788346oswald-lab sshd[3793588]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-18T03:54:04.406169oswald-lab sshd[3793588]: Failed password for root from 121.11.238.49 port 57610 ssh2
...
show less
2026-07-17T18:45:43.788669+02:00 milkyway sshd[3805209]: Failed password for root from 121.11.238.49 ...
show more2026-07-17T18:45:43.788669+02:00 milkyway sshd[3805209]: Failed password for root from 121.11.238.49 port 40066 ssh2
2026-07-17T18:45:46.702510+02:00 milkyway sshd[3805217]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.11.238.49 user=root
2026-07-17T18:45:49.244589+02:00 milkyway sshd[3805217]: Failed password for root from 121.11.238.49 port 44598 ssh2
...
show less