This IP address has been reported a total of
71
times from
66 distinct
sources.
150.136.54.218 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-30T17:09:37.721734+02:00 mail sshd[3567246]: Failed password for user from 150.136.54.218 po ...
show more2026-09-30T17:09:37.721734+02:00 mail sshd[3567246]: Failed password for user from 150.136.54.218 port 53360 ssh2
2026-09-30T17:12:38.708197+02:00 mail sshd[3567331]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=150.136.54.218 user=root
2026-09-30T17:12:40.252515+02:00 mail sshd[3567331]: Failed password for root from 150.136.54.218 port 38908 ssh2
2026-09-30T17:15:40.968361+02:00 mail sshd[3567459]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=150.136.54.218 user=user
2026-09-30T17:15:42.833566+02:00 mail sshd[3567459]: Failed password for user from 150.136.54.218 port 39140 ssh2
...
show less
(mod_security) mod_security (id:218420) triggered by 150.136.54.218 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:218420) triggered by 150.136.54.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:56:45.927746 2026] [security2:error] [pid 7701:tid 7701] [client 150.136.54.218:43796] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.25:80|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.25"] [uri "/hello.world"] [unique_id "ar0jLTU9gxh21E5TZYRKygAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/. ...
show moreBot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e
show less
Sep 30 14:42:24 agera sshd[364534]: Invalid user user from 150.136.54.218 port 57718
Sep 30 14:42:24 ...
show moreSep 30 14:42:24 agera sshd[364534]: Invalid user user from 150.136.54.218 port 57718
Sep 30 14:42:24 agera sshd[364534]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=150.136.54.218
Sep 30 14:42:26 agera sshd[364534]: Failed password for invalid user user from 150.136.54.218 port 57718 ssh2
...
show less
Sep 30 14:40:30 mail6 sshd-session[2676399]: Failed password for invalid user admin from 150.136.54. ...
show moreSep 30 14:40:30 mail6 sshd-session[2676399]: Failed password for invalid user admin from 150.136.54.218 port 53406 ssh2
Sep 30 14:42:35 mail6 sshd-session[2677279]: Invalid user user from 150.136.54.218 port 41116
Sep 30 14:42:35 mail6 sshd-session[2677279]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=150.136.54.218
Sep 30 14:42:36 mail6 sshd-session[2677279]: Failed password for invalid user user from 150.136.54.218 port 41116 ssh2
Sep 30 14:44:38 mail6 sshd-session[2678274]: User root from 150.136.54.218 not allowed because not listed in AllowUsers
...
show less
Blocked by https://aegis.hr โ Fail2ban IP Ban - (MITRE T1110.001), 2 attempts, Period: 2026-09-30 12 ...
show moreBlocked by https://aegis.hr โ Fail2ban IP Ban - (MITRE T1110.001), 2 attempts, Period: 2026-09-30 12:08:35 to 2026-09-30 12:08:35
show less