This IP address has been reported a total of
19
times from
17 distinct
sources.
154.219.114.209 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
United States of America
with 3
reports;
Canada
with 2
reports.
The most common categories in these recent reports were:
SSH
12
times;
Brute-Force
12
times;
Port Scan
9
times;
Hacking
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
2026-09-16T12:16:27.412094+00:00 Linux101 sshd[863146]: pam_unix(sshd:auth): authentication failure; ...
show more2026-09-16T12:16:27.412094+00:00 Linux101 sshd[863146]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.219.114.209 user=root
2026-09-16T12:16:30.063090+00:00 Linux101 sshd[863146]: Failed password for root from 154.219.114.209 port 33610 ssh2
2026-09-16T12:16:34.051962+00:00 Linux101 sshd[863146]: Failed password for root from 154.219.114.209 port 33610 ssh2
2026-09-16T12:16:37.737471+00:00 Linux101 sshd[863146]: Failed password for root from 154.219.114.209 port 33610 ssh2
2026-09-16T12:16:40.893533+00:00 Linux101 sshd[863146]: Failed password for root from 154.219.114.209 port 33610 ssh2
2026-09-16T12:16:44.099187+00:00 Linux101 sshd[863146]: Disconnecting authenticating user root 154.219.114.209 port 33610: Change of username or service not allowed: (root,ssh-connection) -> (test,ssh-connection) [preauth]
2026-09-16T12:16:47.391812+00:00 Linux101 sshd[865230]: Invalid user test from 154.219.114.209 port 35962
2026-09-16T12:16:47.393046+0
...
show less
Automated report: SSH brute force detected. This IP exceeded the allowed number of failed login atte ...
show moreAutomated report: SSH brute force detected. This IP exceeded the allowed number of failed login attempts (3 attempts).
show less
Port scan from this IP. Firewall dropped every packet. Targeted TCP ports: 2222. Single burst at 202 ...
show morePort scan from this IP. Firewall dropped every packet. Targeted TCP ports: 2222. Single burst at 2026-09-15 13:12 UTC.
show less
Sep 14 14:42:28 ChazTelPlex sshd[1583885]: Failed password for root from 154.219.114.209 port 59872 ...
show moreSep 14 14:42:28 ChazTelPlex sshd[1583885]: Failed password for root from 154.219.114.209 port 59872 ssh2
Sep 14 14:42:43 ChazTelPlex sshd[1583885]: Disconnecting authenticating user root 154.219.114.209 port 59872: Change of username or service not allowed: (root,ssh-connection) -> (test,ssh-connection) [preauth]
...
show less
[07:03] Wiped the Redis keyspace with FLUSHDB (0 key(s)) - matches the ransomware/wiper pattern of c ...
show more[07:03] Wiped the Redis keyspace with FLUSHDB (0 key(s)) - matches the ransomware/wiper pattern of connecting unauthenticated and destroying data
show less