This IP address has been reported a total of
27
times from
19 distinct
sources.
125.163.201.253 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Jun 9 08:57:17 vmi790109 sshd[2870756]: Invalid user jcseg-server from 125.163.201.253 port 40246
J ...
show moreJun 9 08:57:17 vmi790109 sshd[2870756]: Invalid user jcseg-server from 125.163.201.253 port 40246
Jun 9 08:57:19 vmi790109 sshd[2870756]: Failed password for invalid user jcseg-server from 125.163.201.253 port 40246 ssh2
Jun 9 08:57:38 vmi790109 sshd[2870758]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=125.163.201.253 user=root
Jun 9 08:57:40 vmi790109 sshd[2870758]: Failed password for root from 125.163.201.253 port 53248 ssh2
Jun 9 08:58:02 vmi790109 sshd[2870763]: Invalid user nagios from 125.163.201.253 port 42036
...
show less
Fail2Ban (sshd): 2 failed attempts. Log sample: Jun 9 08:54:49 server sshd[1232279]: Connection clo ...
show moreFail2Ban (sshd): 2 failed attempts. Log sample: Jun 9 08:54:49 server sshd[1232279]: Connection closed by 125.163.201.253 port 54182 [preauth]
Jun 9 08:56:58 server sshd[1237101]: Connection closed by authenticating user root 125.163.201.253 port 36044 [preauth]
show less
CrowdSec IDS alert on VPS 85.215.198.123 (DE). Scenario: local/ssh-bf-slow
Brute-Force
SSH
Anonymous
2026-06-08_11:01:27.70581 User root from 125.163.201.253 not allowed because not listed in AllowUser ...
show more2026-06-08_11:01:27.70581 User root from 125.163.201.253 not allowed because not listed in AllowUsers
2026-06-08_11:01:50.65943 User root from 125.163.201.253 not allowed because not listed in AllowUsers
show less
2026-06-07T17:45:31.158754+02:00 hosting.lenzdevelopment.pl sshd-session[40630]: pam_unix(sshd:auth) ...
show more2026-06-07T17:45:31.158754+02:00 hosting.lenzdevelopment.pl sshd-session[40630]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=125.163.201.253
2026-06-07T17:45:33.230808+02:00 hosting.lenzdevelopment.pl sshd-session[40630]: Failed password for invalid user pgpool from 125.163.201.253 port 40030 ssh2
2026-06-07T17:45:49.887653+02:00 hosting.lenzdevelopment.pl sshd-session[40634]: Invalid user ael from 125.163.201.253 port 39218
2026-06-07T17:45:50.066261+02:00 hosting.lenzdevelopment.pl sshd-session[40634]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=125.163.201.253
2026-06-07T17:45:51.874636+02:00 hosting.lenzdevelopment.pl sshd-session[40634]: Failed password for invalid user ael from 125.163.201.253 port 39218 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-06-07T15:41:29.304632+00:00 ubuntu1 sshd[2506713]: Connection closed by 125.163.201.253 port 39 ...
show more2026-06-07T15:41:29.304632+00:00 ubuntu1 sshd[2506713]: Connection closed by 125.163.201.253 port 39002 [preauth]
2026-06-07T15:45:04.916855+00:00 ubuntu1 sshd[2508869]: Connection closed by authenticating user root 125.163.201.253 port 49216 [preauth]
2026-06-07T15:45:25.254155+00:00 ubuntu1 sshd[2509058]: Invalid user pgpool from 125.163.201.253 port 59276
...
show less
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
Jun 3 18:28:02 fell sshd[55273]: User root from 125.163.201.253 not allowed because not listed in A ...
show moreJun 3 18:28:02 fell sshd[55273]: User root from 125.163.201.253 not allowed because not listed in AllowUsers
Jun 3 18:28:25 fell sshd[55275]: User root from 125.163.201.253 not allowed because not listed in AllowUsers
Jun 3 18:28:48 fell sshd[55277]: Invalid user yqtong from 125.163.201.253 port 50888
...
show less
Jun 2 09:03:19 v220250758066366549 sshd[17280]: Invalid user wcl from 125.163.201.253 port 36440
Ju ...
show moreJun 2 09:03:19 v220250758066366549 sshd[17280]: Invalid user wcl from 125.163.201.253 port 36440
Jun 2 09:03:20 v220250758066366549 sshd[17280]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=125.163.201.253
Jun 2 09:03:22 v220250758066366549 sshd[17280]: Failed password for invalid user wcl from 125.163.201.253 port 36440 ssh2
... RK-Cloud
show less
2026-06-01T16:23:25.259796 vmi2089077.contaboserver.net sshd[1853655]: Invalid user work from 125.16 ...
show more2026-06-01T16:23:25.259796 vmi2089077.contaboserver.net sshd[1853655]: Invalid user work from 125.163.201.253 port 54066
2026-06-01T16:23:49.257011 vmi2089077.contaboserver.net sshd[1853805]: Invalid user huawei from 125.163.201.253 port 47360
2026-06-01T16:24:53.068345 vmi2089077.contaboserver.net sshd[1854219]: Invalid user git from 125.163.201.253 port 56952
...
show less
Brute-Force
SSH
Showing 1 to
15
of 27 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ