This IP address has been reported a total of
32
times from
22 distinct
sources.
154.58.4.134 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 9
reports;
United States of America
with 5
reports;
Korea (the Republic of)
with 3
reports.
The most common categories in these recent reports were:
Brute-Force
28
times;
SSH
23
times;
Hacking
7
times;
Exploited Host
5
times;
Port Scan
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
SSH Brute force: 38 attempts were recorded from 154.58.4.134
2026-10-07T21:28:47+02:00 Invalid user ...
show moreSSH Brute force: 38 attempts were recorded from 154.58.4.134
2026-10-07T21:28:47+02:00 Invalid user steam from 154.58.4.134 port 54414
2026-10-07T21:28:54+02:00 Invalid user debian from 154.58.4.134 port 54494
2026-10-07T21:28:58+02:00 Invalid user test from 154.58.4.134 port 54561
2026-10-07T21:29:05+02:00 Invalid user devuser from 154.58.4.134 port 54622
2026-10-07T21:29:11+02:00 Connection closed by authenticating user root 154.58.4.134 port 54720 [preauth]
2026-10-07T21:29:16+02:00 Invalid user ubuntu from 154.58.4.134 port 54798
2026-10-07T21:29:21+02:00 Invalid user fa from 154.58.4.134 port 54855
2026-10-07T21:29:28+02:00 Connection closed by authenticating user root 154.58.4.134 port 54913 [preauth]
2026-10-07T21:29:32+02:00 Invalid user testuser from 154.58.4.134 port 55009
2026-10-07T21:29:37+02:00 Connection closed by authenticating user root 154.58.4.134 port 55059 [preauth]
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted mul ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted multiple logins against our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-10-04 03:31 to 2026-10-06 14:01 UTC | 2 sessions | 28 events | SSH (port 22)
Attack chain:
1. 2 credential attempts: root/$-@A1wUB+3jiQKU, root/123
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/10/154.58.4.134.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
Unsolicited SSH brute-force against port 22 on my small self-hosted server. 6 failed authentication ...
show moreUnsolicited SSH brute-force against port 22 on my small self-hosted server. 6 failed authentication attempts inside the fail2ban detection window triggered an automatic ban (jail sshd). Publickey-only auth means no attempt here could have succeeded -- this is untargeted scanning. Repeat offenses from this address get exponentially longer bans. Reported automatically by fail2ban; no manual review.
show less