This IP address has been reported a total of
636
times from
133 distinct
sources.
137.59.54.34 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-05-20T16:12:15.087136+00:00 mta sshd[215965]: Disconnected from authenticating user root 137.59 ...
show more2026-05-20T16:12:15.087136+00:00 mta sshd[215965]: Disconnected from authenticating user root 137.59.54.34 port 34030 [preauth]
...
show less
2026-05-20T23:54:53.740573+09:00 no5 sshd[984608]: Disconnected from authenticating user root 137.59 ...
show more2026-05-20T23:54:53.740573+09:00 no5 sshd[984608]: Disconnected from authenticating user root 137.59.54.34 port 48862 [preauth]
...
show less
May 20 07:43:19 racetecweb sshd[222002]: User root from 137.59.54.34 not allowed because not listed ...
show moreMay 20 07:43:19 racetecweb sshd[222002]: User root from 137.59.54.34 not allowed because not listed in AllowUsers
May 20 07:43:19 racetecweb sshd[222002]: error: maximum authentication attempts exceeded for invalid user root from 137.59.54.34 port 47866 ssh2 [preauth]
May 20 16:01:01 racetecweb sshd[230662]: User root from 137.59.54.34 not allowed because not listed in AllowUsers
...
show less
2026-05-20T22:22:47.073719+09:00 no3 sshd[1544745]: Disconnected from authenticating user root 137.5 ...
show more2026-05-20T22:22:47.073719+09:00 no3 sshd[1544745]: Disconnected from authenticating user root 137.59.54.34 port 38594 [preauth]
...
show less
2026-05-20T15:29:28.434102+03:00 vatnik sshd[94730]: User root from 137.59.54.34 not allowed because ...
show more2026-05-20T15:29:28.434102+03:00 vatnik sshd[94730]: User root from 137.59.54.34 not allowed because listed in DenyUsers
...
show less
7 attempts since 08.05.2026 12:45:17 UTC - last one: 2026-05-20T13:32:56.217260+02:00 beta sshd-sess ...
show more7 attempts since 08.05.2026 12:45:17 UTC - last one: 2026-05-20T13:32:56.217260+02:00 beta sshd-session[68583]: Disconnected from authenticating user root 137.59.54.34 port 42794 [preauth]
show less
Unwanted traffic detected by honeypot on May 19, 2026: brute force and hacking attacks (5 over ssh).
Port Scan
Brute-Force
SSH
Anonymous
2026-05-19T23:03:50.658558-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.5 ...
show more2026-05-19T23:03:50.658558-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.59.54.34 port 36412 ssh2: ED25519 SHA256:UOPal+haA6hgDUinnJPO/xb7omMTc2Rb18PmfF09gS4
2026-05-19T23:03:50.939499-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.59.54.34 port 36412 ssh2: RSA SHA256:/p3kKdLRtsv+sBFWEXeCp7/QLREXg4LC/krWJG4sAaw
2026-05-19T23:03:51.220631-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.59.54.34 port 36412 ssh2: RSA SHA256:AD6KCrE3OaB4wV/Kga/SGTqn5TloGc0j8V/3QaoXkuo
2026-05-19T23:03:51.504355-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.59.54.34 port 36412 ssh2: RSA SHA256:HCKjW4WMz8V086LCASxRuyeQsfr+JsmF5zstR5fWmGc
2026-05-19T23:03:51.785631-07:00 hessvillage.com sshd[3240272]: Failed publickey for root from 137.59.54.34 port 36412 ssh2: RSA SHA256:NGWhBlVoJuseneSVBk8aBOJtbWEdVBadB7SGVel3bbE
...
show less
6 attempts since 08.05.2026 12:45:17 UTC - last one: 2026-05-20T07:48:47.620405+02:00 beta sshd-sess ...
show more6 attempts since 08.05.2026 12:45:17 UTC - last one: 2026-05-20T07:48:47.620405+02:00 beta sshd-session[59136]: Disconnected from authenticating user root 137.59.54.34 port 38668 [preauth]
show less
Cowrie Honeypot: 2 unauthorised SSH/Telnet login attempts between 2026-05-20T03:01:10Z and 2026-05-2 ...
show moreCowrie Honeypot: 2 unauthorised SSH/Telnet login attempts between 2026-05-20T03:01:10Z and 2026-05-20T03:01:10Z
show less
Brute-Force
SSH
Showing 211 to
225
of 636 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ