This IP address has been reported a total of
67
times from
56 distinct
sources.
142.93.91.2 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Probed system info via reconnaissance commands across two sessions. Session 1: authenticated as mysq ...
show moreProbed system info via reconnaissance commands across two sessions. Session 1: authenticated as mysql with password "username"; Session 2: oneadmin with password "oneadmin". Both weak default creds. SSH client is Go-based, suggesting automated scanning framework. Three commands executed: uname variant (kernel details), lspci filtered for GPU enum (VGA/graphics), uptime probe. Command sequence indicates fingerprinting for system capabilities and hardwareβtypical precursor to exploitation or lateral movement. No persistence, downloads, or cmd injection observed. Activity targets misconfigured/default credential deployments. Low sophistication but systematic pattern consistent with automated credential spray attacks against database services/management interfaces. No successful secondary access or post-exploitation activity detected in captured timeframe.
show less
2026-08-31T11:05:11.215683+02:00 host1 sshd[203991]: Failed password for mysql from 142.93.91.2 port ...
show more2026-08-31T11:05:11.215683+02:00 host1 sshd[203991]: Failed password for mysql from 142.93.91.2 port 38900 ssh2
2026-08-31T11:07:58.824783+02:00 host1 sshd[204975]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2 user=mysql
2026-08-31T11:08:01.505939+02:00 host1 sshd[204975]: Failed password for mysql from 142.93.91.2 port 47924 ssh2
2026-08-31T11:07:58.824783+02:00 host1 sshd[204975]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2 user=mysql
2026-08-31T11:08:01.505939+02:00 host1 sshd[204975]: Failed password for mysql from 142.93.91.2 port 47924 ssh2
...
show less
Aug 31 17:54:15 starlight-server sshd[2408021]: Failed password for invalid user splunk from 142.93. ...
show moreAug 31 17:54:15 starlight-server sshd[2408021]: Failed password for invalid user splunk from 142.93.91.2 port 36718 ssh2
Aug 31 17:57:16 starlight-server sshd[2410910]: Invalid user nginx from 142.93.91.2 port 42918
Aug 31 17:57:16 starlight-server sshd[2410910]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2
Aug 31 17:57:18 starlight-server sshd[2410910]: Failed password for invalid user nginx from 142.93.91.2 port 42918 ssh2
Aug 31 18:00:13 starlight-server sshd[2413745]: Invalid user mysql from 142.93.91.2 port 59916
...
show less
2026-08-31T10:54:53.602451 proxy-ssh.dsi.uvsq.fr sshd[1043096]: Failed password for invalid user spl ...
show more2026-08-31T10:54:53.602451 proxy-ssh.dsi.uvsq.fr sshd[1043096]: Failed password for invalid user splunk from 142.93.91.2 port 35614 ssh2
2026-08-31T10:54:55.530676 proxy-ssh.dsi.uvsq.fr sshd[1043096]: Connection closed by invalid user splunk 142.93.91.2 port 35614 [preauth]
2026-08-31T10:57:53.653059 proxy-ssh.dsi.uvsq.fr sshd[1043119]: Invalid user nginx from 142.93.91.2 port 54540
2026-08-31T10:57:53.812017 proxy-ssh.dsi.uvsq.fr sshd[1043119]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2
2026-08-31T10:57:55.772381 proxy-ssh.dsi.uvsq.fr sshd[1043119]: Failed password for invalid user nginx from 142.93.91.2 port 54540 ssh2
...
show less
2026-08-31T04:43:10.544165-04:00 xrb.astro.sunysb.edu sshd-session[27078]: Invalid user user from 14 ...
show more2026-08-31T04:43:10.544165-04:00 xrb.astro.sunysb.edu sshd-session[27078]: Invalid user user from 142.93.91.2 port 39690
2026-08-31T04:43:10.616559-04:00 xrb.astro.sunysb.edu sshd-session[27078]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2
2026-08-31T04:43:12.435450-04:00 xrb.astro.sunysb.edu sshd-session[27078]: Failed password for invalid user user from 142.93.91.2 port 39690 ssh2
2026-08-31T04:43:10.616559-04:00 xrb.astro.sunysb.edu sshd-session[27078]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2
2026-08-31T04:43:12.435450-04:00 xrb.astro.sunysb.edu sshd-session[27078]: Failed password for invalid user user from 142.93.91.2 port 39690 ssh2
...
show less
Brute-Force
SSH
Anonymous
suricata IPS/IDS detection, ruleset ET SCAN Potential SSH Scan
Aug 31 10:29:04 fw01 sshd[811125]: Invalid user sonar from 142.93.91.2 port 48610
Aug 31 10:31:55 fw ...
show moreAug 31 10:29:04 fw01 sshd[811125]: Invalid user sonar from 142.93.91.2 port 48610
Aug 31 10:31:55 fw01 sshd[811142]: Invalid user master from 142.93.91.2 port 39334
Aug 31 10:31:55 fw01 sshd[811142]: Invalid user master from 142.93.91.2 port 39334
...
show less
2026-08-31T10:20:18.864402 proxy-ssh.dsi.uvsq.fr sshd[1042672]: Failed password for invalid user ora ...
show more2026-08-31T10:20:18.864402 proxy-ssh.dsi.uvsq.fr sshd[1042672]: Failed password for invalid user oracle from 142.93.91.2 port 43720 ssh2
2026-08-31T10:20:20.835470 proxy-ssh.dsi.uvsq.fr sshd[1042672]: Connection closed by invalid user oracle 142.93.91.2 port 43720 [preauth]
2026-08-31T10:23:11.935280 proxy-ssh.dsi.uvsq.fr sshd[1042703]: Invalid user oracle from 142.93.91.2 port 47828
2026-08-31T10:23:12.094045 proxy-ssh.dsi.uvsq.fr sshd[1042703]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=142.93.91.2
2026-08-31T10:23:14.034443 proxy-ssh.dsi.uvsq.fr sshd[1042703]: Failed password for invalid user oracle from 142.93.91.2 port 47828 ssh2
...
show less
Aug 31 10:08:44 hydrogen sshd[985763]: Invalid user oracle from 142.93.91.2 port 37754
Aug 31 10:11: ...
show moreAug 31 10:08:44 hydrogen sshd[985763]: Invalid user oracle from 142.93.91.2 port 37754
Aug 31 10:11:38 hydrogen sshd[987487]: Invalid user oracle from 142.93.91.2 port 41568
Aug 31 10:14:22 hydrogen sshd[988919]: Invalid user oracle from 142.93.91.2 port 38978
Aug 31 10:17:11 hydrogen sshd[990214]: Invalid user oracle from 142.93.91.2 port 45902
Aug 31 10:20:03 hydrogen sshd[991643]: Invalid user oracle from 142.93.91.2 port 58184
...
show less
conducted reconnaissance of system hardware and OS configuration across 5 sessions using Go-based SS ...
show moreconducted reconnaissance of system hardware and OS configuration across 5 sessions using Go-based SSH client. Attempted access with 5 oracle-account credential variants (1q2w3e4r, Oracle1234, oracle1234a, q1w2e3r4, qwer1234), all following weak password patterns. Commands focused on GPU enumeration: queried uname for kernel/architecture details, executed lspci filters targeting "3D controller" and VGA devices, ran nvidia-smi queries to enumerate GPU product names and count available accelerators. Also checked system uptime. No malware downloads, file transfers, or persistence mechanisms observed. No lateral movement attempts or port forwarding. Attack pattern indicates scanning for GPU-equipped systems, potentially for cryptomining or ML workload targeting. Activity confined to single IP with no outbound callbacks detected during sessions.
show less