Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
139.0.22.6 has been reported 1,465
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 139.0.22.6:
This IP address has been reported a total of
1,465
times from
481 distinct
sources.
139.0.22.6 was first reported on
, and the most recent report was
.
Mar 9 04:22:05 roki2 sshd\[18256\]: Invalid user ansible from 139.0.22.6
Mar 9 04:22:05 roki2 sshd ...
show moreMar 9 04:22:05 roki2 sshd\[18256\]: Invalid user ansible from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18261\]: Invalid user guest from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18265\]: Invalid user admin from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18271\]: Invalid user gitlab-runner from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18259\]: Invalid user testuser from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18262\]: Invalid user ubuntu from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18266\]: Invalid user testuser from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18284\]: Invalid user tester from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18272\]: Invalid user admin from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18279\]: Invalid user student from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18264\]: Invalid user ftpuser from 139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18256\]: pam_unix\(sshd:auth\): authentication failure\; logname= uid=0 euid=0 tty=ssh ruser= rhost=139.0.22.6
Mar 9 04:22:05 roki2 sshd\[18257\]: pam_unix\(
...
show less
2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:0 ...
show more2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:09:32,625 fail2ban.actions [585]: NOTICE [pam-generic] Ban 139.0.22.6
show less
2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:0 ...
show more2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:09:32,625 fail2ban.actions [585]: NOTICE [pam-generic] Ban 139.0.22.6
show less
SSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect ...
show moreSSH login attempts (SSH bruteforce attack). For more information, or to report interesting/incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:0 ...
show more2023-03-10 03:09:32,547 fail2ban.actions [585]: NOTICE [sshd] Ban 139.0.22.6
2023-03-10 03:09:32,625 fail2ban.actions [585]: NOTICE [pam-generic] Ban 139.0.22.6
show less
A brute-force attempt has been detected from 139.0.22.6 (Indonesia / West Java / Bandung) with 16 di ...
show moreA brute-force attempt has been detected from 139.0.22.6 (Indonesia / West Java / Bandung) with 16 distinct account(s) and 20 distinct password(s) over 0s.
show less
ThreatBook Intelligence: Zombie,Brute Force more details on https://threatbook.io/ip/139.0.22.6
2023 ...
show moreThreatBook Intelligence: Zombie,Brute Force more details on https://threatbook.io/ip/139.0.22.6
2023-03-13 05:00:08 ["uname -a"]
2023-03-13 05:00:08 ["uname -a"]
2023-03-13 05:00:08 ["uname -a"]
2023-03-13 05:00:08 ["uname -a"]
show less
Probed for vulnerable web application: request line: /phpMyAdmin/scripts/setup.php (Possible exploit ...
show moreProbed for vulnerable web application: request line: /phpMyAdmin/scripts/setup.php (Possible exploit:PHPMyadmin installation)
show less