This IP address has been reported a total of
25
times from
22 distinct
sources.
138.197.91.234 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Port scan / connection attempts on ports 465/TCP, 3333/TCP, 6666/TCP, 8880/TCP to unused IP
Port Scan
Anonymous
unsolicited connect TCP dport 7173 (sport 61008)
Hacking
Anonymous
denied traffic to a honeypot network. destination port 4449.
Cowrie Honeypot: 10 unauthorised SSH/Telnet login attempts between 2026-03-11T17:05:27Z and 2026-03- ...
show moreCowrie Honeypot: 10 unauthorised SSH/Telnet login attempts between 2026-03-11T17:05:27Z and 2026-03-11T17:16:40Z
show less
2026-03-11T17:04:18.989959+00:00 api sshd[147637]: Connection closed by 138.197.91.234 port 38948
20 ...
show more2026-03-11T17:04:18.989959+00:00 api sshd[147637]: Connection closed by 138.197.91.234 port 38948
2026-03-11T17:06:10.851329+00:00 api sshd[147652]: Connection closed by authenticating user root 138.197.91.234 port 43354 [preauth]
2026-03-11T17:07:25.825397+00:00 api sshd[147672]: Connection closed by authenticating user root 138.197.91.234 port 46644 [preauth]
2026-03-11T17:08:42.462039+00:00 api sshd[147701]: Connection closed by authenticating user root 138.197.91.234 port 57304 [preauth]
2026-03-11T17:09:58.317140+00:00 api sshd[147714]: Connection closed by authenticating user root 138.197.91.234 port 57830 [preauth]
...
show less
2026-03-11T18:06:57.437548+01:00 vmd172806 sshd[1142854]: Failed password for root from 138.197.91.2 ...
show more2026-03-11T18:06:57.437548+01:00 vmd172806 sshd[1142854]: Failed password for root from 138.197.91.234 port 60140 ssh2
2026-03-11T18:08:11.082956+01:00 vmd172806 sshd[1143140]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.91.234 user=root
2026-03-11T18:08:13.058551+01:00 vmd172806 sshd[1143140]: Failed password for root from 138.197.91.234 port 41258 ssh2
...
show less
2026-03-11T17:06:57.043550+00:00 polaris sshd[1891771]: Failed password for root from 138.197.91.234 ...
show more2026-03-11T17:06:57.043550+00:00 polaris sshd[1891771]: Failed password for root from 138.197.91.234 port 57656 ssh2
2026-03-11T17:08:10.739012+00:00 polaris sshd[1891963]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.91.234 user=root
2026-03-11T17:08:12.242908+00:00 polaris sshd[1891963]: Failed password for root from 138.197.91.234 port 50536 ssh2
...
show less
2026-03-11T18:06:51.126591+01:00 dArtagnan sshd[3638199]: Failed password for root from 138.197.91.2 ...
show more2026-03-11T18:06:51.126591+01:00 dArtagnan sshd[3638199]: Failed password for root from 138.197.91.234 port 49728 ssh2
2026-03-11T18:08:05.487804+01:00 dArtagnan sshd[3638837]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.91.234 user=root
2026-03-11T18:08:06.971444+01:00 dArtagnan sshd[3638837]: Failed password for root from 138.197.91.234 port 59344 ssh2
...
show less
Report 2134199 with IP 3181761 for SSH brute-force attack by source 3176424 via ssh-honeypot/0.2.1+h ...
show moreReport 2134199 with IP 3181761 for SSH brute-force attack by source 3176424 via ssh-honeypot/0.2.1+http
show less
2026-03-12T01:06:12.164522+08:00 vmi996132.contaboserver.net sshd[4168874]: Connection closed by aut ...
show more2026-03-12T01:06:12.164522+08:00 vmi996132.contaboserver.net sshd[4168874]: Connection closed by authenticating user root 138.197.91.234 port 38828 [preauth]
2026-03-12T01:07:22.944936+08:00 vmi996132.contaboserver.net sshd[4168935]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.91.234 user=root
2026-03-12T01:07:25.193111+08:00 vmi996132.contaboserver.net sshd[4168935]: Failed password for root from 138.197.91.234 port 35360 ssh2
...
show less
Blocked by CrowdSec Server Protection.
Attack type: crowdsecurity/ssh-slow-bf
Source Country: US
Tim ...
show moreBlocked by CrowdSec Server Protection.
Attack type: crowdsecurity/ssh-slow-bf
Source Country: US
Time (UTC): 2026-03-11T17:05:18.338378548Z
show less
Mar 11 18:06:27 dalia sshd[84883]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid= ...
show moreMar 11 18:06:27 dalia sshd[84883]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.197.91.234 user=root
Mar 11 18:06:29 dalia sshd[84883]: Failed password for root from 138.197.91.234 port 55382 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 25 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ