Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 135.129.162.142
This IP address has been reported a total of
14
times from
14 distinct
sources.
135.129.162.142 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 7
reports;
Canada
with 2
reports;
Australia
with 1
report.
The most common categories in these recent reports were:
Brute-Force
11
times;
SSH
11
times;
Port Scan
3
times;
Hacking
2
times;
Web App Attack
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-22T08:44:01.466084+02:00 Debian-trixie-latest-amd64-base sshd-session[1841024]: Failed passw ...
show more2026-09-22T08:44:01.466084+02:00 Debian-trixie-latest-amd64-base sshd-session[1841024]: Failed password for invalid user ubuntu from 135.129.162.142 port 48156 ssh2
2026-09-22T08:44:06.288891+02:00 Debian-trixie-latest-amd64-base sshd-session[1841290]: Invalid user test from 135.129.162.142 port 43742
2026-09-22T08:44:07.290954+02:00 Debian-trixie-latest-amd64-base sshd-session[1841290]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=135.129.162.142
2026-09-22T08:44:09.374051+02:00 Debian-trixie-latest-amd64-base sshd-session[1841290]: Failed password for invalid user test from 135.129.162.142 port 43742 ssh2
...
show less
TSEC Honeypot Network report. Threat score: 70/100. Categories: Port Scan, Brute-Force, SSH. Honeypo ...
show moreTSEC Honeypot Network report. Threat score: 70/100. Categories: Port Scan, Brute-Force, SSH. Honeypot: beelzebub. Context: Attacker IP from Farmington, United States (AS13614, All West Communications, Inc.
show less
Active SSH brute-force detected. Logs: 2026-09-20T21:24:07.641742+00:00 AVM-564551RITUAL sshd[271626 ...
show moreActive SSH brute-force detected. Logs: 2026-09-20T21:24:07.641742+00:00 AVM-564551RITUAL sshd[271626]: Failed password for invalid user deploy from 135.129.162.142 port 39502 ssh2 2026-09-20T21:24:13.238092+00:00 AVM-564551RITUAL sshd[271628]: Invalid ...
show less
SSH Brute Force (3 attempts). Evidence: sshd:auth): authentication failure; logname= uid=0 euid=0 tt ...
show moreSSH Brute Force (3 attempts). Evidence: sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=135.129.162.142;sshd-session[558525]: Failed password for invalid user nexus from 135.129.162.142 port 46762 ssh2
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted mul ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted multiple logins against our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-09-20 18:07 to 2026-09-20 18:40 UTC | 2 sessions | 28 events | SSH (port 22)
Attack chain:
1. 2 credential attempts: ansible/ansible, test/123456
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/135.129.162.142.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
2026-09-20T07:46:51.950049-07:00 project-furina sshd[3608709]: Connection closed by authenticating u ...
show more2026-09-20T07:46:51.950049-07:00 project-furina sshd[3608709]: Connection closed by authenticating user root 135.129.162.142 port 46386 [preauth]
2026-09-20T07:46:52.446164-07:00 project-furina sshd[3608731]: Connection closed by authenticating user root 135.129.162.142 port 46426 [preauth]
2026-09-20T07:46:52.810058-07:00 project-furina sshd[3608805]: Invalid user cs2server from 135.129.162.142 port 46472
...
show less
2026-09-20T18:17:56.869562+10:00 smtp.geddy.au sshd-session[2058122]: Failed password for invalid us ...
show more2026-09-20T18:17:56.869562+10:00 smtp.geddy.au sshd-session[2058122]: Failed password for invalid user db2fenc1 from 135.129.162.142 port 43288 ssh2
2026-09-20T18:17:59.527867+10:00 smtp.geddy.au sshd-session[2058124]: Invalid user oracle from 135.129.162.142 port 50106
2026-09-20T18:17:59.715998+10:00 smtp.geddy.au sshd-session[2058124]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=135.129.162.142
2026-09-20T18:18:02.137004+10:00 smtp.geddy.au sshd-session[2058124]: Failed password for invalid user oracle from 135.129.162.142 port 50106 ssh2
...
show less
SSH
Showing 1 to
14
of 14 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ