This IP address has been reported a total of
32
times from
16 distinct
sources.
138.121.44.221 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Participating in DDoS Amplification Attack! Sending 13 requests over 45862s asking for ?0? of cisco. ...
show moreParticipating in DDoS Amplification Attack! Sending 13 requests over 45862s asking for ?0? of cisco.com, atlassian.com, apple.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 18 requests over 46217s asking for ?0? of apple. ...
show moreParticipating in DDoS Amplification Attack! Sending 18 requests over 46217s asking for ?0? of apple.com, atlassian.com, cisco.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 19 requests over 26101s asking for ?0? of apple. ...
show moreParticipating in DDoS Amplification Attack! Sending 19 requests over 26101s asking for ?0? of apple.com, atlassian.com, cisco.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Nov 3 18:00:53 xxx sshd[13450]: Connection from 138.121.44.221 port 19709
Nov 3 18:00:55 xxx sshd[ ...
show moreNov 3 18:00:53 xxx sshd[13450]: Connection from 138.121.44.221 port 19709
Nov 3 18:00:55 xxx sshd[13450]: Address 138.121.44.221 maps to 221-44-121-138.eagleredes.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 3 18:00:55 xxx sshd[13450]: debug1: PAM: setting PAM_RHOST to "138.121.44.221"
Nov 3 18:00:55 xxx sshd[13450]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.44.221 user=r.r
Nov 3 18:00:57 xxx sshd[13450]: Failed password for r.r from 138.121.44.221 port 19709 ssh2
Nov 3 18:00:57 xxx sshd[13450]: Received disconnect from 138.121.44.221: 11: Bye Bye [preauth]
Nov 3 18:01:57 xxx sshd[13471]: Connection from 138.121.44.221 port 24024
Nov 3 18:01:59 xxx sshd[13471]: Address 138.121.44.221 maps to 221-44-121-13
.... truncated ....
4-121-138.eagleredes.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 5 02:44:47 xxx sshd[26984]: debug1: PAM: s........
-------------------------------
show less
2021-11-14T10:26:13.943116Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:131 ...
show more2021-11-14T10:26:13.943116Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:13194 (173.249.29.137:2222) [session: c419d4855a1a]
2021-11-14T11:52:09.508461Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:16152 (173.249.29.137:2222) [session: 8b82ab07b6be]
...
show less
SSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect ...
show moreSSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect findings, give me a shoutout on @parthmaniar on Twitter.
show less
2021-11-13T18:38:27.292741Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:112 ...
show more2021-11-13T18:38:27.292741Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:11203 (173.249.29.137:2222) [session: 69193bfff0e2]
2021-11-13T20:04:19.783245Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:58601 (173.249.29.137:2222) [session: f72ac9a6856e]
...
show less
SSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect ...
show moreSSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect findings, give me a shoutout on @parthmaniar on Twitter.
show less
2021-10-28T03:52:39.680217Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:199 ...
show more2021-10-28T03:52:39.680217Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:19926 (173.249.29.137:2222) [session: b4488ed1e2c4]
2021-10-28T05:17:00.615116Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:7920 (173.249.29.137:2222) [session: d85f837d3975]
...
show less
2021-10-27T12:25:13.282471Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:257 ...
show more2021-10-27T12:25:13.282471Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:25748 (173.249.29.137:2222) [session: 7d483b734fc1]
2021-10-27T13:49:37.195567Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:21663 (173.249.29.137:2222) [session: 7e0bd96c772e]
...
show less
2021-10-26T19:41:38.212928Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:405 ...
show more2021-10-26T19:41:38.212928Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:40542 (173.249.29.137:2222) [session: 4bf15ee231bd]
2021-10-26T21:04:11.309266Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:63324 (173.249.29.137:2222) [session: 9fdedc5b3c4c]
...
show less
2021-10-19T03:48:00.654075Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:312 ...
show more2021-10-19T03:48:00.654075Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:31247 (173.249.29.137:2222) [session: feeaa3e0ebb1]
2021-10-19T05:12:00.703015Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:20964 (173.249.29.137:2222) [session: 46ec78fd3efc]
...
show less
2021-10-18T11:22:54.807051Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:527 ...
show more2021-10-18T11:22:54.807051Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:52723 (173.249.29.137:2222) [session: 560a2fb63448]
2021-10-18T12:44:14.691103Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 138.121.44.221:43076 (173.249.29.137:2222) [session: c95c5163ec89]
...
show less
Brute-Force
Showing 1 to
15
of 32 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ