This IP address has been reported a total of
35
times from
29 distinct
sources.
154.241.51.1 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Fail2Ban sshd: repeated SSH login failures (possible brute-force) detected by automated security too ...
show moreFail2Ban sshd: repeated SSH login failures (possible brute-force) detected by automated security tooling. Technical log details and local server identifiers intentionally omitted for privacy.
show less
2026-08-31T16:29:12.361776 server8.ohost.net sshd[143623]: pam_unix(sshd:auth): authentication failu ...
show more2026-08-31T16:29:12.361776 server8.ohost.net sshd[143623]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.241.51.1
2026-08-31T16:29:14.473752 server8.ohost.net sshd[143623]: Failed password for invalid user terraria from 154.241.51.1 port 49880 ssh2
2026-08-31T16:32:06.516401 server8.ohost.net sshd[146816]: Invalid user systems from 154.241.51.1 port 59644
2026-08-31T16:32:06.527662 server8.ohost.net sshd[146816]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.241.51.1
2026-08-31T16:32:08.193747 server8.ohost.net sshd[146816]: Failed password for invalid user systems from 154.241.51.1 port 59644 ssh2
...
show less
2026-08-31T12:46:54.376224+00:00 ginemed-prod sshd[2526611]: Invalid user lfc from 154.241.51.1 port ...
show more2026-08-31T12:46:54.376224+00:00 ginemed-prod sshd[2526611]: Invalid user lfc from 154.241.51.1 port 49194
2026-08-31T12:52:25.002033+00:00 ginemed-prod sshd[2526876]: Invalid user ubuntu from 154.241.51.1 port 57594
2026-08-31T12:53:46.991599+00:00 ginemed-prod sshd[2526896]: Invalid user suporte from 154.241.51.1 port 59076
...
show less
2026-08-31T12:11:37.106853 socky.stom66.co.uk sshd[2609225]: Invalid user fred from 154.241.51.1 por ...
show more2026-08-31T12:11:37.106853 socky.stom66.co.uk sshd[2609225]: Invalid user fred from 154.241.51.1 port 55248
2026-08-31T12:15:53.922485 socky.stom66.co.uk sshd[2611656]: Invalid user support from 154.241.51.1 port 60996
...
show less
SSH brute force on port 22 -- 21 attempts, 1 successful. Credentials: root:123456q., debian:123@123A ...
show moreSSH brute force on port 22 -- 21 attempts, 1 successful. Credentials: root:123456q., debian:123@123Aa, 345gs5662d34:310310. Active: 2026-08-31T06:47 to 2026-08-31T08:03. Post-login: /usr/bin/env python3 /usr/local/bin/honeypot_pam.py; /usr/sbin/sshd -D -R; ausearch -i -k command --checkpoint /var/lib/honeypot/audit_. Malware: trojan (critical); trojan (high); miner (critical). Source: AS36947 Telecom Algeria (Bab Ezzouar, DZ). Data from SSH honeypot โ not a production system.
show less
Aug 31 11:42:36 jump sshd[2185170]: Failed password for root from 154.241.51.1 port 56900 ssh2
Aug 3 ...
show moreAug 31 11:42:36 jump sshd[2185170]: Failed password for root from 154.241.51.1 port 56900 ssh2
Aug 31 11:44:16 jump sshd[2185231]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.241.51.1 user=root
Aug 31 11:44:18 jump sshd[2185231]: Failed password for root from 154.241.51.1 port 48806 ssh2
...
show less
Aug 31 11:13:39 jump sshd[2184186]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid ...
show moreAug 31 11:13:39 jump sshd[2184186]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.241.51.1 user=root
Aug 31 11:13:41 jump sshd[2184186]: Failed password for root from 154.241.51.1 port 33732 ssh2
Aug 31 11:16:27 jump sshd[2184293]: Invalid user carto from 154.241.51.1 port 41112
...
show less
Detected by CrowdSec on web-6405131d: CrowdSec: crowdsecurity/ssh-slow-bf | ASN: 36947 (Telecom Alge ...
show moreDetected by CrowdSec on web-6405131d: CrowdSec: crowdsecurity/ssh-slow-bf | ASN: 36947 (Telecom Algeria) | Country: DZ | Range: 154.240.0.0/12
show less
Fail2Ban sshd: repeated SSH login failures (possible brute-force) detected by automated security too ...
show moreFail2Ban sshd: repeated SSH login failures (possible brute-force) detected by automated security tooling. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Aug 31 10:45:10 jump sshd[2183204]: Failed password for invalid user pentest from 154.241.51.1 port ...
show moreAug 31 10:45:10 jump sshd[2183204]: Failed password for invalid user pentest from 154.241.51.1 port 58804 ssh2
Aug 31 10:54:14 jump sshd[2183478]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.241.51.1 user=root
Aug 31 10:54:16 jump sshd[2183478]: Failed password for root from 154.241.51.1 port 37150 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-08-31T12:53:28.466599 localhost.localdomain sshd-session[1605096]: Failed password for root fro ...
show more2026-08-31T12:53:28.466599 localhost.localdomain sshd-session[1605096]: Failed password for root from 154.241.51.1 port 35900 ssh2
2026-08-31T12:53:30.125306 localhost.localdomain sshd-session[1605096]: Disconnected from authenticating user root 154.241.51.1 port 35900 [preauth]
...
show less
Aug 31 09:39:51 mail sshd[1073505]: Invalid user gateway from 154.241.51.1 port 44908
Aug 31 09:53:4 ...
show moreAug 31 09:39:51 mail sshd[1073505]: Invalid user gateway from 154.241.51.1 port 44908
Aug 31 09:53:47 mail sshd[1073831]: Invalid user ubuntu from 154.241.51.1 port 37046
Aug 31 09:56:24 mail sshd[1073870]: Invalid user reza from 154.241.51.1 port 50442
Aug 31 09:57:40 mail sshd[1073896]: Invalid user zxy from 154.241.51.1 port 43846
Aug 31 10:00:43 mail sshd[1073976]: Invalid user sftpuser from 154.241.51.1 port 34036
...
show less