This IP address has been reported a total of
135
times from
80 distinct
sources.
147.93.159.30 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
147.93.159.30 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale ...
show more147.93.159.30 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale industrial operation attempting unrelenting brute-force login attempts for months on end - between all CIDR ranges in the botnet, our servers receive over 800 authentication attempts per minute on smtp, imap and relative mail ports, as well as ssh, and other protocols.
IP INFO:
- IP 147.93.159.30
- Anycast false
- City N/A
- Region N/A
- Region Code N/A
- Country N/A (N/A)
- Continent N/A (N/A)
- Range N/A
- Provider N/A
- Organisation N/A
- Proxy N/A
- Type N/A
show less
Jun 9 04:57:48 Tower sshd-session[915663]: Received disconnect from 147.93.159.30 port 57370:11: By ...
show moreJun 9 04:57:48 Tower sshd-session[915663]: Received disconnect from 147.93.159.30 port 57370:11: Bye Bye [preauth]
Jun 9 04:57:48 Tower sshd-session[915663]: Disconnected from invalid user postgres 147.93.159.30 port 57370 [preauth]
Jun 9 04:57:48 Tower sshd[3606]: srclimit_penalise: ipv4: new 147.93.159.30/32 deferred penalty of 5 seconds for penalty: failed authentication
show less
Cowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-09T08:46:53Z and 2026-06-0 ...
show moreCowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-09T08:46:53Z and 2026-06-09T08:51:49Z
show less
Jun 9 09:32:29 EMIRATESofBULGARIA sshd[179746]: Failed password for invalid user buser from 147.93. ...
show moreJun 9 09:32:29 EMIRATESofBULGARIA sshd[179746]: Failed password for invalid user buser from 147.93.159.30 port 46314 ssh2
Jun 9 09:34:35 EMIRATESofBULGARIA sshd[179756]: Invalid user idf from 147.93.159.30 port 34234
Jun 9 09:34:35 EMIRATESofBULGARIA sshd[179756]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.93.159.30
Jun 9 09:34:35 EMIRATESofBULGARIA sshd[179756]: Invalid user idf from 147.93.159.30 port 34234
Jun 9 09:34:37 EMIRATESofBULGARIA sshd[179756]: Failed password for invalid user idf from 147.93.159.30 port 34234 ssh2
Jun 9 09:36:47 EMIRATESofBULGARIA sshd[179772]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.93.159.30 user=root
Jun 9 09:36:48 EMIRATESofBULGARIA sshd[179772]: Failed password for root from 147.93.159.30 port 42920 ssh2
...
show less
2026-06-09T09:31:21.854937+02:00 pve-osd-101 sshd[629913]: Invalid user dev from 147.93.159.30 port ...
show more2026-06-09T09:31:21.854937+02:00 pve-osd-101 sshd[629913]: Invalid user dev from 147.93.159.30 port 39224
2026-06-09T09:31:21.856984+02:00 pve-osd-101 sshd[629913]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.93.159.30
2026-06-09T09:31:21.862705+02:00 pve-osd-101 sshd[629913]: pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=147.93.159.30 user=dev
2026-06-09T09:31:23.520749+02:00 pve-osd-101 sshd[629913]: Failed password for invalid user dev from 147.93.159.30 port 39224 ssh2
2026-06-09T09:31:23.807143+02:00 pve-osd-101 sshd[629913]: Disconnected from invalid user dev 147.93.159.30 port 39224 [preauth]
2026-06-09T09:33:31.660429+02:00 pve-osd-101 sshd[629969]: Invalid user buser from 147.93.159.30 port 53698
...
show less
Jun 9 08:55:55 server1 sshd[4006193]: Invalid user karen from 147.93.159.30 port 38390
Jun 9 09:00 ...
show moreJun 9 08:55:55 server1 sshd[4006193]: Invalid user karen from 147.93.159.30 port 38390
Jun 9 09:00:36 server1 sshd[4007013]: Invalid user gns3 from 147.93.159.30 port 58836
Jun 9 09:02:54 server1 sshd[4007352]: Invalid user jira from 147.93.159.30 port 52440
...
show less
Jun 9 08:25:25 server1 sshd[4001594]: Invalid user nico from 147.93.159.30 port 43414
Jun 9 08:27: ...
show moreJun 9 08:25:25 server1 sshd[4001594]: Invalid user nico from 147.93.159.30 port 43414
Jun 9 08:27:46 server1 sshd[4001955]: Invalid user user2 from 147.93.159.30 port 56564
Jun 9 08:34:49 server1 sshd[4003028]: Invalid user ubuntu from 147.93.159.30 port 42344
...
show less
Jun 9 06:12:30 antti-vps2 sshd[288985]: User root from 147.93.159.30 not allowed because none of us ...
show moreJun 9 06:12:30 antti-vps2 sshd[288985]: User root from 147.93.159.30 not allowed because none of user's groups are listed in AllowGroups
Jun 9 06:14:34 antti-vps2 sshd[289317]: Connection from 147.93.159.30 port 59624 on 10.0.0.124 port 22 rdomain ""
Jun 9 06:14:35 antti-vps2 sshd[289317]: Invalid user webserver from 147.93.159.30 port 59624
Jun 9 06:16:32 antti-vps2 sshd[289601]: Connection from 147.93.159.30 port 60516 on 10.0.0.124 port 22 rdomain ""
Jun 9 06:16:33 antti-vps2 sshd[289601]: User root from 147.93.159.30 not allowed because none of user's groups are listed in AllowGroups
...
show less
Jun 9 08:05:36 server1 sshd[3998648]: Invalid user bank from 147.93.159.30 port 35870
Jun 9 08:10: ...
show moreJun 9 08:05:36 server1 sshd[3998648]: Invalid user bank from 147.93.159.30 port 35870
Jun 9 08:10:02 server1 sshd[3999220]: Invalid user boss from 147.93.159.30 port 49860
Jun 9 08:14:20 server1 sshd[3999918]: Invalid user webserver from 147.93.159.30 port 47990
...
show less
2026-06-09T06:03:55.267530+00:00 edge-nik-ams01.int.pdx.net.uk sshd-session[187672]: Invalid user ba ...
show more2026-06-09T06:03:55.267530+00:00 edge-nik-ams01.int.pdx.net.uk sshd-session[187672]: Invalid user bank from 147.93.159.30 port 44764
2026-06-09T06:09:48.984167+00:00 edge-nik-ams01.int.pdx.net.uk sshd-session[188171]: Invalid user boss from 147.93.159.30 port 48562
2026-06-09T06:14:05.965712+00:00 edge-nik-ams01.int.pdx.net.uk sshd-session[188526]: Invalid user webserver from 147.93.159.30 port 44010
...
show less
Brute-Force
SSH
Showing 1 to
15
of 135 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ