This IP address has been reported a total of
37
times from
33 distinct
sources.
150.158.196.236 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS ...
show moreVerified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS=22 | HITS=2 | IPSET=ADD | FIRST=2026-06-17 16:59:32 | LAST=2026-06-17 16:59:32. Last seen 2026-06-17 16:59:32.
show less
2026-06-17T16:29:13.242511+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 1 ...
show more2026-06-17T16:29:13.242511+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 150.158.196.236 port 47030 ssh2
2026-06-17T16:29:16.860979+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 150.158.196.236 port 47030 ssh2
2026-06-17T16:29:21.164364+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 150.158.196.236 port 47030 ssh2
2026-06-17T16:29:23.540409+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 150.158.196.236 port 47030 ssh2
2026-06-17T16:29:25.750062+03:00 vps1770900684 sshd-session[627099]: Failed password for root from 150.158.196.236 port 47030 ssh2
...
show less
Active SSH brute-force detected. Logs: 2026-06-15T21:02:59.801754+00:00 AVM-506798 sshd[68752]: Fail ...
show moreActive SSH brute-force detected. Logs: 2026-06-15T21:02:59.801754+00:00 AVM-506798 sshd[68752]: Failed password for root from 150.158.196.236 port 37078 ssh2 2026-06-15T21:03:02.998403+00:00 AVM-506798 sshd[68752]: Failed password for root from 150.158...
show less
2026-06-08T21:06:14.681451+00:00 seraph sshd[36385]: Failed password for invalid user root from 150. ...
show more2026-06-08T21:06:14.681451+00:00 seraph sshd[36385]: Failed password for invalid user root from 150.158.196.236 port 45302 ssh2
2026-06-08T21:06:29.363083+00:00 seraph sshd[36385]: Disconnecting invalid user root 150.158.196.236 port 45302: Change of username or service not allowed: (root,ssh-connection) -> (test,ssh-connection) [preauth]
2026-06-08T21:06:30.767546+00:00 seraph sshd[36545]: Invalid user test from 150.158.196.236 port 48754
2026-06-08T21:06:30.769746+00:00 seraph sshd[36545]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=150.158.196.236
2026-06-08T21:06:33.231634+00:00 seraph sshd[36545]: Failed password for invalid user test from 150.158.196.236 port 48754 ssh2
...
show less
Hit on SSH honeypot at 2026-06-02 04:05:19 from 150.158.196.236 as user root with password kPFQQaqSB ...
show moreHit on SSH honeypot at 2026-06-02 04:05:19 from 150.158.196.236 as user root with password kPFQQaqSBn
show less
May 31 02:44:52 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 5883 ...
show moreMay 31 02:44:52 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 58834 ssh2
May 31 02:44:54 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 58834 ssh2
May 31 02:44:57 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 58834 ssh2
May 31 02:44:59 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 58834 ssh2
May 31 02:45:02 srv-ubuntu-dev3 sshd[28007]: Failed password for root from 150.158.196.236 port 58834 ssh2
...
show less
2026-05-30T06:19:51.105817+03:00 6kw sshd[1661988]: Failed password for root from 150.158.196.236 po ...
show more2026-05-30T06:19:51.105817+03:00 6kw sshd[1661988]: Failed password for root from 150.158.196.236 port 36036 ssh2
...
show less
2026-05-30T10:28:48.027751+09:00 no1 sshd[2071663]: Connection closed by authenticating user root 15 ...
show more2026-05-30T10:28:48.027751+09:00 no1 sshd[2071663]: Connection closed by authenticating user root 150.158.196.236 port 58442 [preauth]
...
show less
Brute-Force
SSH
Showing 1 to
15
of 37 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ