This IP address has been reported a total of
756
times from
352 distinct
sources.
138.197.39.208 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(sshd) Failed SSH login from 138.197.39.208 (US/United States/-): 5 in the last 3600 secs; Ports: *; ...
show more(sshd) Failed SSH login from 138.197.39.208 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 30 14:08:35 13963 sshd[4564]: Invalid user admin from 138.197.39.208 port 40692
May 30 14:08:38 13963 sshd[4564]: Failed password for invalid user admin from 138.197.39.208 port 40692 ssh2
May 30 14:09:10 13963 sshd[4840]: Invalid user orangepi from 138.197.39.208 port 36388
May 30 14:09:12 13963 sshd[4840]: Failed password for invalid user orangepi from 138.197.39.208 port 36388 ssh2
May 30 14:09:46 13963 sshd[4955]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 user=root
show less
Blocked by UFW on vps4 [2375/tcp]
Source port: 45485
TTL: 56
Packet length: 40
TOS: 0x00
This repor ...
show moreBlocked by UFW on vps4 [2375/tcp]
Source port: 45485
TTL: 56
Packet length: 40
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show moreHoneypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
(mod_security) mod_security (id:949110) triggered by 138.197.39.208 (US/United States/-): N in the l ...
show more(mod_security) mod_security (id:949110) triggered by 138.197.39.208 (US/United States/-): N in the last X secs
show less
2026-05-30T19:02:10.198354+03:00 fastdl sshd[4022896]: Invalid user orangepi from 138.197.39.208 por ...
show more2026-05-30T19:02:10.198354+03:00 fastdl sshd[4022896]: Invalid user orangepi from 138.197.39.208 port 35158
2026-05-30T19:02:10.205902+03:00 fastdl sshd[4022896]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208
2026-05-30T19:02:11.952795+03:00 fastdl sshd[4022896]: Failed password for invalid user orangepi from 138.197.39.208 port 35158 ssh2
2026-05-30T19:02:44.510242+03:00 fastdl sshd[4022911]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 user=root
2026-05-30T19:02:46.593482+03:00 fastdl sshd[4022911]: Failed password for root from 138.197.39.208 port 49952 ssh2
...
show less
[Fail2Ban:sshd-spray] 2026-05-30T14:32:29.144661+02:00 server sshd[1850577]: pam_unix(sshd:auth): au ...
show more[Fail2Ban:sshd-spray] 2026-05-30T14:32:29.144661+02:00 server sshd[1850577]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 2026-05-30T14:32:31.072316+02:00 server sshd[1850577]: Failed password for invalid user orangepi from 138.197.39.208 port 42116 ssh2 2026-05-30T14:33:09.431073+02:00 server sshd[1851139]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 user=root 2026-05-30T14:33:10.847805+02:00 server sshd[1851139]: Failed password for root from 138.197.39.208 port 38708 ssh2 2026-05-30T14:33:50.378019+02:00 server sshd[1851713]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 user=root 2026-05-30T14:33:52.426593+02:00 server sshd[1851713]: Failed password for root from 138.197.39.208 port 34982 ssh2
show less
2026-05-30T10:15:29.727594+00:00 hel.updn.io sshd[258646]: Invalid user orangepi from 138.197.39.208 ...
show more2026-05-30T10:15:29.727594+00:00 hel.updn.io sshd[258646]: Invalid user orangepi from 138.197.39.208 port 36406
2026-05-30T10:15:29.733556+00:00 hel.updn.io sshd[258646]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208
2026-05-30T10:15:32.199203+00:00 hel.updn.io sshd[258646]: Failed password for invalid user orangepi from 138.197.39.208 port 36406 ssh2
2026-05-30T10:16:06.848213+00:00 hel.updn.io sshd[261404]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208 user=root
2026-05-30T10:16:08.727068+00:00 hel.updn.io sshd[261404]: Failed password for root from 138.197.39.208 port 38194 ssh2
...
show less
2026-05-30T08:26:34.543310+00:00 ubuntu-4gb-fsn1-2 sshd[2554714]: Invalid user orangepi from 138.197 ...
show more2026-05-30T08:26:34.543310+00:00 ubuntu-4gb-fsn1-2 sshd[2554714]: Invalid user orangepi from 138.197.39.208 port 35438
2026-05-30T08:26:34.551149+00:00 ubuntu-4gb-fsn1-2 sshd[2554714]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.39.208
2026-05-30T08:26:36.873005+00:00 ubuntu-4gb-fsn1-2 sshd[2554714]: Failed password for invalid user orangepi from 138.197.39.208 port 35438 ssh2
...
show less
2026-05-30T08:03:20.827253+00:00 worker-lon1 sshd[2665998]: Invalid user admin from 138.197.39.208 p ...
show more2026-05-30T08:03:20.827253+00:00 worker-lon1 sshd[2665998]: Invalid user admin from 138.197.39.208 port 50862
2026-05-30T08:03:51.893315+00:00 worker-lon1 sshd[2666002]: Invalid user orangepi from 138.197.39.208 port 48466
2026-05-30T08:07:36.695927+00:00 worker-lon1 sshd[2666042]: Invalid user test from 138.197.39.208 port 35314
2026-05-30T08:08:08.953636+00:00 worker-lon1 sshd[2666046]: Invalid user user from 138.197.39.208 port 55632
2026-05-30T08:09:11.067232+00:00 worker-lon1 sshd[2666055]: Invalid user admin from 138.197.39.208 port 57492
...
show less
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login atte ...
show moreAutomated report: SSH brute force detected. This IP exceeded the allowed number of failed login attempts (3 attempts).
show less
Brute-Force
SSH
Showing 91 to
105
of 756 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ