This IP address has been reported a total of
204
times from
134 distinct
sources.
157.85.111.20 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Jun 2 04:07:30 srv-ubuntu-dev3 sshd[28360]: Failed password for invalid user xh from 157.85.111.20 ...
show moreJun 2 04:07:30 srv-ubuntu-dev3 sshd[28360]: Failed password for invalid user xh from 157.85.111.20 port 33496 ssh2
Jun 2 04:07:30 srv-ubuntu-dev3 sshd[28360]: Disconnected from invalid user xh 157.85.111.20 port 33496 [preauth]
Jun 2 04:11:13 srv-ubuntu-dev3 sshd[29046]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20 user=root
Jun 2 04:11:16 srv-ubuntu-dev3 sshd[29046]: Failed password for root from 157.85.111.20 port 50676 ssh2
Jun 2 04:11:16 srv-ubuntu-dev3 sshd[29046]: Disconnected from authenticating user root 157.85.111.20 port 50676 [preauth]
...
show less
Jun 2 03:52:25 srv-ubuntu-dev3 sshd[26179]: Disconnected from authenticating user root 157.85.111.2 ...
show moreJun 2 03:52:25 srv-ubuntu-dev3 sshd[26179]: Disconnected from authenticating user root 157.85.111.20 port 53656 [preauth]
Jun 2 03:56:09 srv-ubuntu-dev3 sshd[26787]: Invalid user acer from 157.85.111.20 port 47514
Jun 2 03:56:09 srv-ubuntu-dev3 sshd[26787]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20
Jun 2 03:56:11 srv-ubuntu-dev3 sshd[26787]: Failed password for invalid user acer from 157.85.111.20 port 47514 ssh2
Jun 2 03:56:11 srv-ubuntu-dev3 sshd[26787]: Disconnected from invalid user acer 157.85.111.20 port 47514 [preauth]
...
show less
Jun 2 03:38:25 srv-ubuntu-dev3 sshd[24089]: Failed password for invalid user gitlab-runner from 157 ...
show moreJun 2 03:38:25 srv-ubuntu-dev3 sshd[24089]: Failed password for invalid user gitlab-runner from 157.85.111.20 port 42170 ssh2
Jun 2 03:38:25 srv-ubuntu-dev3 sshd[24089]: Disconnected from invalid user gitlab-runner 157.85.111.20 port 42170 [preauth]
Jun 2 03:40:09 srv-ubuntu-dev3 sshd[24549]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20 user=root
Jun 2 03:40:11 srv-ubuntu-dev3 sshd[24549]: Failed password for root from 157.85.111.20 port 52354 ssh2
Jun 2 03:40:11 srv-ubuntu-dev3 sshd[24549]: Disconnected from authenticating user root 157.85.111.20 port 52354 [preauth]
...
show less
Jun 2 03:07:56 srv-ubuntu-dev3 sshd[19470]: Failed password for invalid user xyh from 157.85.111.20 ...
show moreJun 2 03:07:56 srv-ubuntu-dev3 sshd[19470]: Failed password for invalid user xyh from 157.85.111.20 port 43792 ssh2
Jun 2 03:07:56 srv-ubuntu-dev3 sshd[19470]: Disconnected from invalid user xyh 157.85.111.20 port 43792 [preauth]
Jun 2 03:14:12 srv-ubuntu-dev3 sshd[20546]: Invalid user tesoreria from 157.85.111.20 port 59052
Jun 2 03:14:12 srv-ubuntu-dev3 sshd[20546]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20
Jun 2 03:14:14 srv-ubuntu-dev3 sshd[20546]: Failed password for invalid user tesoreria from 157.85.111.20 port 59052 ssh2
...
show less
2026-06-01T20:32:58.527370-04:00 debian sshd[3610532]: Failed password for invalid user contact from ...
show more2026-06-01T20:32:58.527370-04:00 debian sshd[3610532]: Failed password for invalid user contact from 157.85.111.20 port 51526 ssh2
2026-06-01T20:38:23.005715-04:00 debian sshd[3615279]: Invalid user setup from 157.85.111.20 port 46260
2026-06-01T20:38:23.009389-04:00 debian sshd[3615279]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20
2026-06-01T20:38:24.904699-04:00 debian sshd[3615279]: Failed password for invalid user setup from 157.85.111.20 port 46260 ssh2
2026-06-01T20:41:27.196485-04:00 debian sshd[3617752]: Invalid user jonas from 157.85.111.20 port 36898
...
show less
2026-06-02T02:29:59.550185+02:00 7of9 sshd-session[998791]: Failed password for invalid user contact ...
show more2026-06-02T02:29:59.550185+02:00 7of9 sshd-session[998791]: Failed password for invalid user contact from 157.85.111.20 port 55538 ssh2
2026-06-02T02:30:00.582302+02:00 7of9 sshd-session[998791]: Disconnected from invalid user contact 157.85.111.20 port 55538 [preauth]
2026-06-02T02:36:20.133565+02:00 7of9 sshd-session[999074]: Invalid user michael from 157.85.111.20 port 52246
2026-06-02T02:36:20.138539+02:00 7of9 sshd-session[999074]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20
2026-06-02T02:36:22.091739+02:00 7of9 sshd-session[999074]: Failed password for invalid user michael from 157.85.111.20 port 52246 ssh2
...
show less
Brute-Force
SSH
Anonymous
Automated report: IP 157.85.111.20 detected in ssh-bruteforce activity on convergentdefense.com. See ...
show moreAutomated report: IP 157.85.111.20 detected in ssh-bruteforce activity on convergentdefense.com. Seen 1x, first: 2026-06-02 00:00. [ISAC-India]
show less
Brute-Force
SSH
Anonymous
Jun 2 07:38:18 mail sshd[22000]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreJun 2 07:38:18 mail sshd[22000]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20
Jun 2 07:38:20 mail sshd[22000]: Failed password for invalid user pedro from 157.85.111.20 port 48694 ssh2
show less
2026-06-01T22:35:52.119324+00:00 mail sshd[81416]: Invalid user leon from 157.85.111.20 port 48076
2 ...
show more2026-06-01T22:35:52.119324+00:00 mail sshd[81416]: Invalid user leon from 157.85.111.20 port 48076
2026-06-01T22:37:31.652461+00:00 mail sshd[81456]: Invalid user git from 157.85.111.20 port 42768
2026-06-01T22:39:02.551099+00:00 mail sshd[81472]: Invalid user jenkins from 157.85.111.20 port 33090
2026-06-01T22:40:37.561956+00:00 mail sshd[81484]: Invalid user manuel from 157.85.111.20 port 42798
2026-06-01T22:43:50.887939+00:00 mail sshd[81515]: Invalid user dev1 from 157.85.111.20 port 40422
...
show less
157.85.111.20 (TH/Thailand/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; P ...
show more157.85.111.20 (TH/Thailand/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 1 16:55:41 21732 sshd[7527]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=157.85.111.20 user=root
Jun 1 16:55:43 21732 sshd[7527]: Failed password for root from 157.85.111.20 port 36922 ssh2
Jun 1 16:57:19 21732 sshd[8438]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.82.39.34 user=root
Jun 1 16:57:22 21732 sshd[8438]: Failed password for root from 103.82.39.34 port 59224 ssh2
Jun 1 16:57:36 21732 sshd[8548]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=144.31.232.96 user=root
IP Addresses Blocked:
show less
Brute-Force
SSH
Showing 1 to
15
of 204 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ