This IP address has been reported a total of
59
times from
47 distinct
sources.
147.136.249.38 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 12
reports;
United Kingdom of Great Britain and Northern Ireland
with 5
reports;
United States of America
with 5
reports.
The most common categories in these recent reports were:
Brute-Force
49
times;
SSH
37
times;
Hacking
11
times;
Web App Attack
11
times;
Port Scan
5
times;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-10-05T00:37:04.399530+02:00 odroidxu4 sshd[27856]: Failed password for root from 147.136.249.38 ...
show more2026-10-05T00:37:04.399530+02:00 odroidxu4 sshd[27856]: Failed password for root from 147.136.249.38 port 47768 ssh2
2026-10-05T00:37:09.035632+02:00 odroidxu4 sshd[27859]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
2026-10-05T00:37:11.107684+02:00 odroidxu4 sshd[27859]: Failed password for root from 147.136.249.38 port 34758 ssh2
...
show less
2026-10-05T00:37:04.399530+02:00 odroidxu4 sshd[27856]: Failed password for root from 147.136.249.38 ...
show more2026-10-05T00:37:04.399530+02:00 odroidxu4 sshd[27856]: Failed password for root from 147.136.249.38 port 47768 ssh2
2026-10-05T00:37:09.035632+02:00 odroidxu4 sshd[27859]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
2026-10-05T00:37:11.107684+02:00 odroidxu4 sshd[27859]: Failed password for root from 147.136.249.38 port 34758 ssh2
...
show less
Synology DSM web login brute-force: 18 failed sign-in attempt(s) between 09:16:04 and 18:50:30 CEST ...
show moreSynology DSM web login brute-force: 18 failed sign-in attempt(s) between 09:16:04 and 18:50:30 CEST on 2026-10-06; part of distributed low-and-slow campaign (1000+ IPs).
show less
This IP address carried out 2 SSH credential attack (attempts) on 05-10-2026. For more information o ...
show moreThis IP address carried out 2 SSH credential attack (attempts) on 05-10-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
Automated Synology DSM brute-force login attempts against TCP/5001. Multiple failed authentication a ...
show moreAutomated Synology DSM brute-force login attempts against TCP/5001. Multiple failed authentication attempts were observed and the source was blocked by DiskStation.
show less
Brute-Force
Anonymous
Web directory scan: 10 requests in 2h 16m (Last path: '/webapi/auth.cgi?account=anggi&api=SYNO.API.A ...
show moreWeb directory scan: 10 requests in 2h 16m (Last path: '/webapi/auth.cgi?account=anggi&api=SYNO.API.Auth&format=sid&method=login&passwd=anggi&session=FileStation&version=6').
show less
Honeypot trap triggered: unsolicited TCP connection(s) to unused port(s) 2222 on a host running no s ...
show moreHoneypot trap triggered: unsolicited TCP connection(s) to unused port(s) 2222 on a host running no such service. There is no legitimate reason to connect to these ports.
Observed 1 connection(s) from 2026-10-04T22:25:15Z to 2026-10-04T22:25:15Z UTC.
2026-10-04T22:25:15Z tcp/2222 data: SSH-2.0-OpenSSH_8.9
Connection was blocked automatically at the firewall. Reported by an automated honeypot.
show less
Port Scan
Hacking
Brute-Force
IoT Targeted
Anonymous
2026-10-05T02:03:58.480489+03:30 digitalogic sshd-session[2974420]: Connection closed by authenticat ...
show more2026-10-05T02:03:58.480489+03:30 digitalogic sshd-session[2974420]: Connection closed by authenticating user root 147.136.249.38 port 8485 [preauth]
2026-10-05T03:01:36.605819+03:30 digitalogic sshd-session[3207257]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
2026-10-05T03:01:38.333354+03:30 digitalogic sshd-session[3207257]: Failed password for root from 147.136.249.38 port 31609 ssh2
...
show less
2026-10-04T23:16:39.554933+00:00 instance-20241105-1951 sshd[3172581]: Connection closed by authenti ...
show more2026-10-04T23:16:39.554933+00:00 instance-20241105-1951 sshd[3172581]: Connection closed by authenticating user root 147.136.249.38 port 49750 [preauth]
...
show less
Oct 4 23:01:34 obsidian sshd[1841596]: error: PAM: Authentication failure for root from 147.136.249 ...
show moreOct 4 23:01:34 obsidian sshd[1841596]: error: PAM: Authentication failure for root from 147.136.249.38
Oct 4 23:07:46 obsidian sshd[1852931]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
Oct 4 23:07:48 obsidian sshd[1852931]: Failed password for root from 147.136.249.38 port 45400 ssh2
...
show less
Brute-Force
SSH
Anonymous
Oct 5 00:55:05 con01 sshd[3261309]: Failed password for root from 147.136.249.38 port 35709 ssh2
Oc ...
show moreOct 5 00:55:05 con01 sshd[3261309]: Failed password for root from 147.136.249.38 port 35709 ssh2
Oct 5 00:58:33 con01 sshd[3268555]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
Oct 5 00:58:36 con01 sshd[3268555]: Failed password for root from 147.136.249.38 port 25061 ssh2
Oct 5 01:04:34 con01 sshd[3281814]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.136.249.38 user=root
Oct 5 01:04:36 con01 sshd[3281814]: Failed password for root from 147.136.249.38 port 38079 ssh2
...
show less