This IP address has been reported a total of
91
times from
51 distinct
sources.
138.121.66.252 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
botnet
DDoS Attack
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
Distributed web crawl (like Mellowtel), likely illicit scraping of AI training data to bypass firewa ...
show moreDistributed web crawl (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions (/forums/forums/thread-post.asp?action=reply&replyto=22319%22e%3Dyes)
show less
May 24 18:58:12 srv01 sshd[3699608]: pam_unix(sshd:auth): authentication failure; logname= uid=0 eui ...
show moreMay 24 18:58:12 srv01 sshd[3699608]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252
May 24 18:58:15 srv01 sshd[3699608]: Failed password for invalid user me from 138.121.66.252 port 38456 ssh2
May 24 19:00:30 srv01 sshd[3715687]: Invalid user user from 138.121.66.252 port 38818
May 24 19:00:30 srv01 sshd[3715687]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252
May 24 19:00:33 srv01 sshd[3715687]: Failed password for invalid user user from 138.121.66.252 port 38818 ssh2
...
show less
Attempts to access SSH server with wrong credentials
SSH
Anonymous
(sshd) Failed SSH login from 138.121.66.252 (BR/Brazil/-): 5 in the last 3600 secs; Ports: *; Direct ...
show more(sshd) Failed SSH login from 138.121.66.252 (BR/Brazil/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: May 24 07:37:36 server5 sshd[8578]: Invalid user ai from 138.121.66.252
May 24 07:37:36 server5 sshd[8578]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252
May 24 07:37:38 server5 sshd[8578]: Failed password for invalid user ai from 138.121.66.252 port 38241 ssh2
May 24 08:25:08 server5 sshd[16502]: Invalid user guest01 from 138.121.66.252
May 24 08:25:08 server5 sshd[16502]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252
show less
May 24 11:03:32 mail sshd[16095]: Failed password for root from 138.121.66.252 port 37974 ssh2
May 2 ...
show moreMay 24 11:03:32 mail sshd[16095]: Failed password for root from 138.121.66.252 port 37974 ssh2
May 24 11:09:34 mail sshd[17290]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252 user=root
May 24 11:09:36 mail sshd[17290]: Failed password for root from 138.121.66.252 port 38159 ssh2
May 24 11:12:50 mail sshd[17860]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252 user=root
May 24 11:12:53 mail sshd[17860]: Failed password for root from 138.121.66.252 port 38118 ssh2
...
show less
May 24 10:09:04 mail sshd[6798]: Failed password for root from 138.121.66.252 port 38543 ssh2
May 24 ...
show moreMay 24 10:09:04 mail sshd[6798]: Failed password for root from 138.121.66.252 port 38543 ssh2
May 24 10:23:01 mail sshd[9221]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252 user=root
May 24 10:23:03 mail sshd[9221]: Failed password for root from 138.121.66.252 port 38473 ssh2
May 24 10:26:11 mail sshd[9819]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252 user=root
May 24 10:26:13 mail sshd[9819]: Failed password for root from 138.121.66.252 port 38255 ssh2
...
show less
May 24 05:01:50 epaper-docker-02 sshd[3121084]: Failed password for invalid user nagios from 138.121 ...
show moreMay 24 05:01:50 epaper-docker-02 sshd[3121084]: Failed password for invalid user nagios from 138.121.66.252 port 38397 ssh2
May 24 05:05:16 epaper-docker-02 sshd[3160174]: Connection from 138.121.66.252 port 38408 on 176.9.120.211 port 22 rdomain ""
May 24 05:05:17 epaper-docker-02 sshd[3160174]: Invalid user vpnuser1 from 138.121.66.252 port 38408
May 24 05:05:17 epaper-docker-02 sshd[3160174]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252
May 24 05:05:19 epaper-docker-02 sshd[3160174]: Failed password for invalid user vpnuser1 from 138.121.66.252 port 38408 ssh2
...
show less
May 24 03:31:29 vpn sshd[1309912]: Failed password for invalid user zabbix from 138.121.66.252 port ...
show moreMay 24 03:31:29 vpn sshd[1309912]: Failed password for invalid user zabbix from 138.121.66.252 port 38428 ssh2
May 24 03:49:21 vpn sshd[1310095]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.121.66.252 user=root
May 24 03:49:23 vpn sshd[1310095]: Failed password for root from 138.121.66.252 port 37980 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 91 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩