This IP address has been reported a total of
232
times from
140 distinct
sources.
138.113.28.120 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Multiple SSH login attempts using random credentials
May 26 15:48:14 fir-newer sshd-session[131327] ...
show moreMultiple SSH login attempts using random credentials
May 26 15:48:14 fir-newer sshd-session[131327]: Failed password for ftpUser from 138.113.28.120 port 39312 ssh2
May 26 15:54:25 fir-newer sshd-session[131357]: Failed password for ubuntu from 138.113.28.120 port 42634 ssh2
show less
This IP address carried out 275 port scanning attempts on 26-05-2026. For more information or to rep ...
show moreThis IP address carried out 275 port scanning attempts on 26-05-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
This IP address carried out 52 SSH credential attack (attempts) on 26-05-2026. For more information ...
show moreThis IP address carried out 52 SSH credential attack (attempts) on 26-05-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
May 27 04:40:49 elasticsearch sshd[1657314]: Invalid user vijay from 138.113.28.120 port 33280
May 2 ...
show moreMay 27 04:40:49 elasticsearch sshd[1657314]: Invalid user vijay from 138.113.28.120 port 33280
May 27 04:42:45 elasticsearch sshd[1657327]: Invalid user mc from 138.113.28.120 port 43108
May 27 04:44:41 elasticsearch sshd[1657329]: Invalid user git from 138.113.28.120 port 38324
...
show less
May 26 22:25:56 bluto sshd[109685]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid ...
show moreMay 26 22:25:56 bluto sshd[109685]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.113.28.120
May 26 22:25:58 bluto sshd[109685]: Failed password for invalid user steam from 138.113.28.120 port 52774 ssh2
May 26 22:34:54 bluto sshd[109872]: Invalid user systemd from 138.113.28.120 port 47106
...
show less
2026-05-27T05:55:52.078331+02:00 vpn sshd[100370]: Invalid user systemd from 138.113.28.120 port 409 ...
show more2026-05-27T05:55:52.078331+02:00 vpn sshd[100370]: Invalid user systemd from 138.113.28.120 port 40926
2026-05-27T06:00:39.951706+02:00 vpn sshd[100417]: Invalid user sample from 138.113.28.120 port 39122
2026-05-27T06:02:31.193524+02:00 vpn sshd[100458]: Invalid user steam from 138.113.28.120 port 34504
...
show less
(sshd) Failed SSH login from 138.113.28.120 (HK/Hong Kong/-): 5 in the last 3600 secs; Ports: *; Dir ...
show more(sshd) Failed SSH login from 138.113.28.120 (HK/Hong Kong/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 26 22:54:39 15634 sshd[7501]: Invalid user systemd from 138.113.28.120 port 43420
May 26 22:54:41 15634 sshd[7501]: Failed password for invalid user systemd from 138.113.28.120 port 43420 ssh2
May 26 23:00:28 15634 sshd[8161]: Invalid user sample from 138.113.28.120 port 49574
May 26 23:00:30 15634 sshd[8161]: Failed password for invalid user sample from 138.113.28.120 port 49574 ssh2
May 26 23:02:18 15634 sshd[8384]: Invalid user steam from 138.113.28.120 port 37202
show less
Brute-Force
SSH
Showing 1 to
15
of 232 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ