This IP address has been reported a total of
15
times from
14 distinct
sources.
125.142.89.4 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 3
reports;
United States of America
with 3
reports;
Korea (the Republic of)
with 2
reports.
The most common categories in these recent reports were:
SSH
12
times;
Brute-Force
12
times;
IoT Targeted
2
times;
Hacking
1
time;
FTP Brute-Force
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-29T06:57:21.477986 socky.stom66.co.uk proftpd[1750230]: session[1750230] 0.0.0.0 (125.142.89 ...
show more2026-09-29T06:57:21.477986 socky.stom66.co.uk proftpd[1750230]: session[1750230] 0.0.0.0 (125.142.89.4[125.142.89.4]): USER admin: no such user found from 125.142.89.4 [125.142.89.4] to ::ffff:5.79.80.26:2222
...
show less
Honeypot [honeypot-ca-sensor1]: Brute-force attack detected on 22/SSH
β’ Credential used: ubnt:ubnt
β’ ...
show moreHoneypot [honeypot-ca-sensor1]: Brute-force attack detected on 22/SSH
β’ Credential used: ubnt:ubnt
β’ Number of login attempts: 1
β’ Client: SSH-2.0-Go
show less
SSH
Anonymous
2026-09-18T15:47:06.186880+03:30 digitalogic sshd-session[3264284]: pam_unix(sshd:auth): authenticat ...
show more2026-09-18T15:47:06.186880+03:30 digitalogic sshd-session[3264284]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=125.142.89.4
2026-09-18T15:47:08.842142+03:30 digitalogic sshd-session[3264284]: Failed password for invalid user AdminGPON from 125.142.89.4 port 51468 ssh2
2026-09-18T15:47:11.222105+03:30 digitalogic sshd-session[3264284]: Connection closed by invalid user AdminGPON 125.142.89.4 port 51468 [preauth]
...
show less
Automated report by DataDream Sentinel.
Repeated SSH authentication failures consistent with credent ...
show moreAutomated report by DataDream Sentinel.
Repeated SSH authentication failures consistent with credential brute-force activity were detected against infrastructure monitored by DataDream.
6 failed-authentication event references were correlated between 2026-09-18 10:23:51 and 10:23:55 UTC.
No successful SSH authentication was observed in the available telemetry.
Reference: DD-AIPDB-20260918-CE40EA27
show less
SSH credential brute-force observed by honeypot.
Source IP: 125.142.89.4
Targeted device: DVR
First ...
show moreSSH credential brute-force observed by honeypot.
Source IP: 125.142.89.4
Targeted device: DVR
First seen: 14 Sep 2026 16:48:50 UTC
Last seen: 14 Sep 2026 16:48:50 UTC
Attempts: 1
Client: SSH-2.0-Go
Sample credentials: user:user
show less
2026-09-10T20:42:24.151360+02:00 r2d2 sshd-session[169890]: Invalid user telecomadmin from 125.142.8 ...
show more2026-09-10T20:42:24.151360+02:00 r2d2 sshd-session[169890]: Invalid user telecomadmin from 125.142.89.4 port 53848
...
show less
2026-09-07T10:05:14.565303+02:00 savine sshd-session[1266985]: Invalid user operator from 125.142.89 ...
show more2026-09-07T10:05:14.565303+02:00 savine sshd-session[1266985]: Invalid user operator from 125.142.89.4 port 53308
...
show less