This IP address has been reported a total of
956
times from
466 distinct
sources.
161.132.38.234 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
(sshd) Failed SSH login from 161.132.38.234 (PE/Peru/-): 5 in the last 3600 secs; Ports: *; Directio ...
show more(sshd) Failed SSH login from 161.132.38.234 (PE/Peru/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 2 12:34:33 15397 sshd[27850]: Invalid user ftpuser from 161.132.38.234 port 35228
Jun 2 12:34:35 15397 sshd[27850]: Failed password for invalid user ftpuser from 161.132.38.234 port 35228 ssh2
Jun 2 12:40:12 15397 sshd[30808]: Invalid user paperless from 161.132.38.234 port 53558
Jun 2 12:40:13 15397 sshd[30808]: Failed password for invalid user paperless from 161.132.38.234 port 53558 ssh2
Jun 2 12:42:21 15397 sshd[31916]: Invalid user bot from 161.132.38.234 port 42474
show less
2026-06-02T10:35:08.842192-07:00 shadownetworks.org sshd[2566717]: Failed password for invalid user ...
show more2026-06-02T10:35:08.842192-07:00 shadownetworks.org sshd[2566717]: Failed password for invalid user ftpuser from 161.132.38.234 port 42066 ssh2
2026-06-02T10:40:16.872981-07:00 shadownetworks.org sshd[2570998]: Invalid user paperless from 161.132.38.234 port 44102
2026-06-02T10:40:16.887694-07:00 shadownetworks.org sshd[2570998]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.132.38.234
2026-06-02T10:40:18.992620-07:00 shadownetworks.org sshd[2570998]: Failed password for invalid user paperless from 161.132.38.234 port 44102 ssh2
2026-06-02T10:42:26.000897-07:00 shadownetworks.org sshd[2572705]: Invalid user bot from 161.132.38.234 port 44512
...
show less
Jun 2 17:30:00 atlas sshd[134705]: Invalid user ftpuser from 161.132.38.234 port 58558
Jun 2 17:39 ...
show moreJun 2 17:30:00 atlas sshd[134705]: Invalid user ftpuser from 161.132.38.234 port 58558
Jun 2 17:39:29 atlas sshd[134733]: Invalid user paperless from 161.132.38.234 port 50264
Jun 2 17:41:39 atlas sshd[134760]: Invalid user bot from 161.132.38.234 port 34282
show less
2026-06-02T17:29:32.632089+00:00 edge-noc-mci01.int.pdx.net.uk sshd[849011]: Invalid user ftpuser fr ...
show more2026-06-02T17:29:32.632089+00:00 edge-noc-mci01.int.pdx.net.uk sshd[849011]: Invalid user ftpuser from 161.132.38.234 port 60126
2026-06-02T17:39:24.986965+00:00 edge-noc-mci01.int.pdx.net.uk sshd[850754]: Invalid user paperless from 161.132.38.234 port 37280
2026-06-02T17:41:35.683842+00:00 edge-noc-mci01.int.pdx.net.uk sshd[851140]: Invalid user bot from 161.132.38.234 port 39746
...
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: ftpuser, Pass: [REDACTED]
Jun 2 16:59:47 c2 sshd[3863514]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreJun 2 16:59:47 c2 sshd[3863514]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.132.38.234
Jun 2 16:59:47 c2 sshd[3863514]: Invalid user casa from 161.132.38.234 port 34406
Jun 2 16:59:49 c2 sshd[3863514]: Failed password for invalid user casa from 161.132.38.234 port 34406 ssh2
Jun 2 17:01:46 c2 sshd[3863545]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.132.38.234 user=root
Jun 2 17:01:47 c2 sshd[3863545]: Failed password for root from 161.132.38.234 port 34766 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-06-02T18:56:10.450956+02:00 de-fsn1-host1 sshd-session[291863]: Invalid user sammy from 161.132 ...
show more2026-06-02T18:56:10.450956+02:00 de-fsn1-host1 sshd-session[291863]: Invalid user sammy from 161.132.38.234 port 60982
2026-06-02T18:58:19.306012+02:00 de-fsn1-host1 sshd-session[292646]: Invalid user nikita from 161.132.38.234 port 34086
2026-06-02T19:00:20.829202+02:00 de-fsn1-host1 sshd-session[293391]: Invalid user casa from 161.132.38.234 port 59154
...
show less
Jun 2 18:55:08 remote.srvfarm.net sshd[134753]: Disconnected from invalid user sammy 161.132.38.234 ...
show moreJun 2 18:55:08 remote.srvfarm.net sshd[134753]: Disconnected from invalid user sammy 161.132.38.234 port 60152 [preauth]
Jun 2 18:57:17 remote.srvfarm.net sshd[135285]: Invalid user nikita from 161.132.38.234 port 37370
Jun 2 18:57:17 remote.srvfarm.net sshd[135285]: Disconnected from invalid user nikita 161.132.38.234 port 37370 [preauth]
Jun 2 18:59:23 remote.srvfarm.net sshd[135804]: Invalid user casa from 161.132.38.234 port 36916
Jun 2 18:59:23 remote.srvfarm.net sshd[135804]: Disconnected from invalid user casa 161.132.38.234 port 36916 [preauth]
show less
Jun 2 10:55:14 kenworth sshd[281402]: Invalid user sammy from 161.132.38.234 port 36576
Jun 2 10:5 ...
show moreJun 2 10:55:14 kenworth sshd[281402]: Invalid user sammy from 161.132.38.234 port 36576
Jun 2 10:55:14 kenworth sshd[281402]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.132.38.234
Jun 2 10:55:17 kenworth sshd[281402]: Failed password for invalid user sammy from 161.132.38.234 port 36576 ssh2
...
show less
161.132.38.234 (PE/Peru/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Port ...
show more161.132.38.234 (PE/Peru/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 2 10:55:36 14279 sshd[5413]: Failed password for root from 1.95.73.177 port 60378 ssh2
Jun 2 10:55:34 14279 sshd[5413]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=1.95.73.177 user=root
Jun 2 11:49:44 14279 sshd[3755]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.132.38.234 user=root
Jun 2 11:49:47 14279 sshd[3755]: Failed password for root from 161.132.38.234 port 53002 ssh2
Jun 2 11:54:47 14279 sshd[6640]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.144.246.97 user=root
IP Addresses Blocked:
1.95.73.177 (CN/China/ecs-1-95-73-177.compute.hwclouds-dns.com)
show less
Brute-Force
SSH
Anonymous
Automated report: IP 161.132.38.234 detected in ssh-bruteforce activity on convergentdefense.com. Se ...
show moreAutomated report: IP 161.132.38.234 detected in ssh-bruteforce activity on convergentdefense.com. Seen 1x, first: 2026-06-02 16:00. [ISAC-India]
show less
2026-06-02T17:51:10.414541+02:00 router01.kfz-heimchen.de sshd-session[2591443]: Invalid user usman ...
show more2026-06-02T17:51:10.414541+02:00 router01.kfz-heimchen.de sshd-session[2591443]: Invalid user usman from 161.132.38.234 port 49084
2026-06-02T17:51:10.607469+02:00 router01.kfz-heimchen.de sshd-session[2591443]: Disconnected from invalid user usman 161.132.38.234 port 49084 [preauth]
2026-06-02T17:55:45.291149+02:00 router01.kfz-heimchen.de sshd-session[2592236]: Disconnected from authenticating user root 161.132.38.234 port 42290 [preauth]
2026-06-02T17:57:29.163498+02:00 router01.kfz-heimchen.de sshd-session[2592558]: Invalid user tttt from 161.132.38.234 port 35726
2026-06-02T17:57:29.356179+02:00 router01.kfz-heimchen.de sshd-session[2592558]: Disconnected from invalid user tttt 161.132.38.234 port 35726 [preauth]
show less
CSF/LFD blocked 161.132.38.234 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH ...
show moreCSF/LFD blocked 161.132.38.234 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH login from 161.132.38.234 (PE/Peru/-): 5 in the last 3600 secs. Evidence: Jun 2 10:45:54 paladin sshd[664688]: Invalid user usman from 161.132.38.234 port 36616
show less
Brute-Force
SSH
Showing 106 to
120
of 956 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ