This IP address has been reported a total of
25
times from
17 distinct
sources.
138.124.29.146 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
138.124.29.146 (SE/Sweden/roveil.ptr.network), 5 distributed sshd attacks on account [root] in the l ...
show more138.124.29.146 (SE/Sweden/roveil.ptr.network), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 12 14:21:30 13646 sshd[16180]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=177.152.42.12 user=root
Jun 12 14:16:59 13646 sshd[13785]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.124.29.146 user=root
Jun 12 14:17:02 13646 sshd[13785]: Failed password for root from 138.124.29.146 port 40878 ssh2
Jun 12 14:12:27 13646 sshd[11632]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=177.152.42.12 user=root
Jun 12 14:12:29 13646 sshd[11632]: Failed password for root from 177.152.42.12 port 52174 ssh2
IP Addresses Blocked:
177.152.42.12 (BR/Brazil/12.42.152.177.bitcom.com.br)
show less
2026-06-13T03:21:32.565295+08:00 us21.cdn.420422709.xyz sshd-session[80671]: Invalid user fuho from ...
show more2026-06-13T03:21:32.565295+08:00 us21.cdn.420422709.xyz sshd-session[80671]: Invalid user fuho from 138.124.29.146 port 50164
2026-06-13T03:21:32.570478+08:00 us21.cdn.420422709.xyz sshd-session[80671]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.124.29.146
2026-06-13T03:21:34.837204+08:00 us21.cdn.420422709.xyz sshd-session[80671]: Failed password for invalid user fuho from 138.124.29.146 port 50164 ssh2
...
show less
Fail2Ban report from jail 'sshd': 2026-06-12T21:16:35.224199+02:00 mail sshd[1833385]: User root fro ...
show moreFail2Ban report from jail 'sshd': 2026-06-12T21:16:35.224199+02:00 mail sshd[1833385]: User root from 138.124.29.146 not allowed because not listed in AllowUsers
...
show less
Jun 12 12:55:30 racknerd-a34c87 sshd[862255]: Failed password for invalid user readonly from 138.124 ...
show moreJun 12 12:55:30 racknerd-a34c87 sshd[862255]: Failed password for invalid user readonly from 138.124.29.146 port 40904 ssh2
Jun 12 12:57:46 racknerd-a34c87 sshd[862309]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.124.29.146 user=root
Jun 12 12:57:48 racknerd-a34c87 sshd[862309]: Failed password for root from 138.124.29.146 port 48802 ssh2
Jun 12 13:02:22 racknerd-a34c87 sshd[862407]: Invalid user ethan from 138.124.29.146 port 32848
Jun 12 13:02:22 racknerd-a34c87 sshd[862407]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.124.29.146
Jun 12 13:02:24 racknerd-a34c87 sshd[862407]: Failed password for invalid user ethan from 138.124.29.146 port 32848 ssh2
...
show less
2026-06-12T17:19:07.387380+00:00 kocer-main-webserver sshd[101937]: Invalid user syncuser from 138.1 ...
show more2026-06-12T17:19:07.387380+00:00 kocer-main-webserver sshd[101937]: Invalid user syncuser from 138.124.29.146 port 24908
2026-06-12T17:19:07.551289+00:00 kocer-main-webserver sshd[101937]: Disconnected from invalid user syncuser 138.124.29.146 port 24908 [preauth]
2026-06-12T17:23:45.631304+00:00 kocer-main-webserver sshd[102388]: Disconnected from authenticating user root 138.124.29.146 port 16040 [preauth]
...
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: deploy, Pass: [REDACTED]
2026-06-12T17:03:00.273130+00:00 kocer-main-webserver sshd[100285]: Invalid user suporte from 138.12 ...
show more2026-06-12T17:03:00.273130+00:00 kocer-main-webserver sshd[100285]: Invalid user suporte from 138.124.29.146 port 35534
2026-06-12T17:03:00.445774+00:00 kocer-main-webserver sshd[100285]: Disconnected from invalid user suporte 138.124.29.146 port 35534 [preauth]
2026-06-12T17:07:37.786339+00:00 kocer-main-webserver sshd[100734]: Invalid user temp from 138.124.29.146 port 56398
...
show less
2026-06-12T16:44:12.726471+00:00 kocer-main-webserver sshd[98644]: Disconnected from authenticating ...
show more2026-06-12T16:44:12.726471+00:00 kocer-main-webserver sshd[98644]: Disconnected from authenticating user root 138.124.29.146 port 45536 [preauth]
2026-06-12T16:46:33.032815+00:00 kocer-main-webserver sshd[98860]: Disconnected from authenticating user root 138.124.29.146 port 23524 [preauth]
2026-06-12T16:48:51.345916+00:00 kocer-main-webserver sshd[99032]: Disconnected from authenticating user root 138.124.29.146 port 45906 [preauth]
...
show less
2026-06-12T16:25:00.726716+00:00 kocer-main-webserver sshd[96777]: Disconnected from authenticating ...
show more2026-06-12T16:25:00.726716+00:00 kocer-main-webserver sshd[96777]: Disconnected from authenticating user root 138.124.29.146 port 38740 [preauth]
2026-06-12T16:28:05.817580+00:00 kocer-main-webserver sshd[97103]: Disconnected from authenticating user root 138.124.29.146 port 16322 [preauth]
2026-06-12T16:30:26.059744+00:00 kocer-main-webserver sshd[97280]: Invalid user root2 from 138.124.29.146 port 49534
...
show less
Brute-Force
SSH
Showing 1 to
15
of 25 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ