This IP address has been reported a total of
189
times from
121 distinct
sources.
158.49.70.49 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
(localhost/crowdsec) crowdsecurity/ssh-bf_user-enum by ip 158.49.70.49 (ES/766) : 4h ban on Ip 158.4 ...
show more(localhost/crowdsec) crowdsecurity/ssh-bf_user-enum by ip 158.49.70.49 (ES/766) : 4h ban on Ip 158.49.70.49
show less
2026-05-23T14:54:33.915711+00:00 edge-con-mia01.int.pdx.net.uk sshd[1460111]: Invalid user vendas fr ...
show more2026-05-23T14:54:33.915711+00:00 edge-con-mia01.int.pdx.net.uk sshd[1460111]: Invalid user vendas from 158.49.70.49 port 44380
2026-05-23T14:54:33.925310+00:00 edge-con-mia01.int.pdx.net.uk sshd[1460111]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T14:54:35.876122+00:00 edge-con-mia01.int.pdx.net.uk sshd[1460111]: Failed password for invalid user vendas from 158.49.70.49 port 44380 ssh2
...
show less
2026-05-23T16:52:15.298044+02:00 s15260644 sshd[1172434]: Invalid user vendas from 158.49.70.49 port ...
show more2026-05-23T16:52:15.298044+02:00 s15260644 sshd[1172434]: Invalid user vendas from 158.49.70.49 port 46664
2026-05-23T16:52:15.308562+02:00 s15260644 sshd[1172434]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:52:17.315573+02:00 s15260644 sshd[1172434]: Failed password for invalid user vendas from 158.49.70.49 port 46664 ssh2
show less
Brute-Force
SSH
Anonymous
(sshd) Failed SSH login from 158.49.70.49 (ES/Spain/-): 5 in the last 300 secs; Ports: *; Direction: ...
show more(sshd) Failed SSH login from 158.49.70.49 (ES/Spain/-): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: 2026-05-23T16:38:23.375123+02:00 web28.sier.online sshd[2966715]: Invalid user deploy from 158.49.70.49 port 52018
2026-05-23T16:38:23.385354+02:00 web28.sier.online sshd[2966715]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:38:24.840965+02:00 web28.sier.online sshd[2966715]: Failed password for invalid user deploy from 158.49.70.49 port 52018 ssh2
2026-05-23T16:41:47.174841+02:00 web28.sier.online sshd[2969085]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49 user=root
2026-05-23T16:41:49.969434+02:00 web28.sier.online sshd[2969085]: Failed password for root from 158.49.70.49 port 54254 ssh2
show less
2026-05-23T14:36:40.991918+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4035213]: Invalid user deploy from ...
show more2026-05-23T14:36:40.991918+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4035213]: Invalid user deploy from 158.49.70.49 port 48528
2026-05-23T14:36:41.040315+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4035213]: Disconnected from invalid user deploy 158.49.70.49 port 48528 [preauth]
...
show less
May 23 16:17:53 Ina sshd[901264]: Failed password for root from 158.49.70.49 port 56100 ssh2
May 23 ...
show moreMay 23 16:17:53 Ina sshd[901264]: Failed password for root from 158.49.70.49 port 56100 ssh2
May 23 16:21:16 Ina sshd[901691]: Invalid user uftp from 158.49.70.49 port 52258
May 23 16:21:16 Ina sshd[901691]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
May 23 16:21:18 Ina sshd[901691]: Failed password for invalid user uftp from 158.49.70.49 port 52258 ssh2
May 23 16:24:38 Ina sshd[901923]: Invalid user testuser from 158.49.70.49 port 39514
...
show less
Brute-Force
SSH
Anonymous
(sshd) Failed SSH login from 158.49.70.49 (ES/Spain/-): 5 in the last 300 secs; Ports: *; Direction: ...
show more(sshd) Failed SSH login from 158.49.70.49 (ES/Spain/-): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: 2026-05-23T16:18:33.877223+02:00 web28.sier.online sshd[2953639]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49 user=root
2026-05-23T16:18:35.964768+02:00 web28.sier.online sshd[2953639]: Failed password for root from 158.49.70.49 port 41102 ssh2
2026-05-23T16:21:59.425863+02:00 web28.sier.online sshd[2955987]: Invalid user uftp from 158.49.70.49 port 47608
2026-05-23T16:21:59.432975+02:00 web28.sier.online sshd[2955987]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:22:01.801722+02:00 web28.sier.online sshd[2955987]: Failed password for invalid user uftp from 158.49.70.49 port 47608 ssh2
show less
Port Scan
Anonymous
2026-05-23T16:21:43.321791+02:00 diazserver sshd[489184]: pam_unix(sshd:auth): authentication failur ...
show more2026-05-23T16:21:43.321791+02:00 diazserver sshd[489184]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:21:45.494445+02:00 diazserver sshd[489184]: Failed password for invalid user uftp from 158.49.70.49 port 54724 ssh2
2026-05-23T16:21:43.321791+02:00 diazserver sshd[489184]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:21:45.494445+02:00 diazserver sshd[489184]: Failed password for invalid user uftp from 158.49.70.49 port 54724 ssh2
...
show less
2026-05-23T14:13:17.841472+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4029507]: Disconnected from authent ...
show more2026-05-23T14:13:17.841472+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4029507]: Disconnected from authenticating user root 158.49.70.49 port 57778 [preauth]
2026-05-23T14:16:44.414962+00:00 ubuntu-s-1vcpu-1gb-lon1-01 sshd[4030340]: Disconnected from authenticating user root 158.49.70.49 port 59684 [preauth]
...
show less
2026-05-23T15:57:17.844497+02:00 Server sshd[695225]: Failed password for invalid user ts3server fro ...
show more2026-05-23T15:57:17.844497+02:00 Server sshd[695225]: Failed password for invalid user ts3server from 158.49.70.49 port 53140 ssh2
2026-05-23T16:07:07.830796+02:00 Server sshd[701751]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49 user=root
2026-05-23T16:07:09.742420+02:00 Server sshd[701751]: Failed password for root from 158.49.70.49 port 36456 ssh2
2026-05-23T16:10:23.012751+02:00 Server sshd[704056]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49 user=root
2026-05-23T16:10:25.832552+02:00 Server sshd[704056]: Failed password for root from 158.49.70.49 port 54330 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-05-23T15:58:31.027512+02:00 diazserver sshd[488869]: Failed password for invalid user ts3server ...
show more2026-05-23T15:58:31.027512+02:00 diazserver sshd[488869]: Failed password for invalid user ts3server from 158.49.70.49 port 33080 ssh2
2026-05-23T16:01:45.657300+02:00 diazserver sshd[488880]: Invalid user ftpuser01 from 158.49.70.49 port 33980
2026-05-23T16:01:45.670997+02:00 diazserver sshd[488880]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
2026-05-23T16:01:47.711823+02:00 diazserver sshd[488880]: Failed password for invalid user ftpuser01 from 158.49.70.49 port 33980 ssh2
...
show less
May 23 15:58:02 Ina sshd[899432]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreMay 23 15:58:02 Ina sshd[899432]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
May 23 15:58:04 Ina sshd[899432]: Failed password for invalid user ts3server from 158.49.70.49 port 39916 ssh2
May 23 16:01:20 Ina sshd[899823]: Invalid user ftpuser01 from 158.49.70.49 port 51840
May 23 16:01:20 Ina sshd[899823]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=158.49.70.49
May 23 16:01:22 Ina sshd[899823]: Failed password for invalid user ftpuser01 from 158.49.70.49 port 51840 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 189 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ