This IP address has been reported a total of
251
times from
80 distinct
sources.
161.248.37.160 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-01T15:51:20.394212+00:00 s158416 sshd[4042633]: Failed password for root from 161.248.37.160 ...
show more2026-09-01T15:51:20.394212+00:00 s158416 sshd[4042633]: Failed password for root from 161.248.37.160 port 47704 ssh2
2026-09-01T15:57:47.634633+00:00 s158416 sshd[4043159]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T15:57:49.504815+00:00 s158416 sshd[4043159]: Failed password for root from 161.248.37.160 port 34686 ssh2
2026-09-01T15:57:47.694415+00:00 s158416 sshd[4043161]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T15:57:49.564374+00:00 s158416 sshd[4043161]: Failed password for root from 161.248.37.160 port 43784 ssh2
...
show less
2026-09-01T21:03:26.423661+05:30 ittifakordusu sshd-session[3264521]: Failed password for root from ...
show more2026-09-01T21:03:26.423661+05:30 ittifakordusu sshd-session[3264521]: Failed password for root from 161.248.37.160 port 57992 ssh2
2026-09-01T21:09:52.250530+05:30 ittifakordusu sshd-session[3272666]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T21:09:53.954869+05:30 ittifakordusu sshd-session[3272666]: Failed password for root from 161.248.37.160 port 36132 ssh2
...
show less
Brute-force SSH attack using Go-based client. Attacker attempted two credential pairs: root/12341234 ...
show moreBrute-force SSH attack using Go-based client. Attacker attempted two credential pairs: root/12341234 and root/12345. Upon gaining access, executed reconnaissance commands targeting system information retrieval: enumeration of /etc/passwd, /etc/shadow, CPU model, kernel version, environment variables, and command history. Created temporary test files in /tmp with timestamps (test_1788275333, test_1788275721), indicating write-access verification. Issued whoami, id, and hostname commands for privilege and system identification. Executed 70 command invocations across 35 unique commands within 7-minute window. No malware downloads, persistence mechanisms (cron, ssh keys, init.d modifications), or lateral movement observed. Attack pattern consistent with initial reconnaissance phase of multi-stage intrusion. Weak credentials targeted suggest opportunistic scanning rather than targeted compromise. No exfiltration channels established during monitoring window.
show less
2026-09-01T15:12:02.669011+00:00 aws.vandogh.org sshd-session[1636850]: Failed password for invalid ...
show more2026-09-01T15:12:02.669011+00:00 aws.vandogh.org sshd-session[1636850]: Failed password for invalid user root from 161.248.37.160 port 59432 ssh2
2026-09-01T15:18:29.675413+00:00 aws.vandogh.org sshd-session[1636894]: User root from 161.248.37.160 not allowed because not listed in AllowUsers
2026-09-01T15:18:30.197809+00:00 aws.vandogh.org sshd-session[1636894]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T15:18:32.378573+00:00 aws.vandogh.org sshd-session[1636894]: Failed password for invalid user root from 161.248.37.160 port 46064 ssh2
...
show less
2026-09-01T20:37:19.094838+05:30 ittifakordusu sshd-session[3231303]: Failed password for root from ...
show more2026-09-01T20:37:19.094838+05:30 ittifakordusu sshd-session[3231303]: Failed password for root from 161.248.37.160 port 39750 ssh2
2026-09-01T20:43:45.344202+05:30 ittifakordusu sshd-session[3239759]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T20:43:47.918055+05:30 ittifakordusu sshd-session[3239759]: Failed password for root from 161.248.37.160 port 53150 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-09-01T14:59:10.046405+00:00 s158416 sshd[4037612]: Failed password for root from 161.248.37.160 ...
show more2026-09-01T14:59:10.046405+00:00 s158416 sshd[4037612]: Failed password for root from 161.248.37.160 port 41070 ssh2
2026-09-01T15:05:42.194862+00:00 s158416 sshd[4038134]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T15:05:43.388324+00:00 s158416 sshd[4038134]: Failed password for root from 161.248.37.160 port 52342 ssh2
2026-09-01T15:05:41.857895+00:00 s158416 sshd[4038136]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T15:05:43.582873+00:00 s158416 sshd[4038136]: Failed password for root from 161.248.37.160 port 40018 ssh2
...
show less
Automated reconnaissance activity from Go-based SSH client. Two sessions targeting root account with ...
show moreAutomated reconnaissance activity from Go-based SSH client. Two sessions targeting root account with weak credentials (root/1234, root/1234!@#$). Attacker executed 35 unique commands focused on system enumeration: OS version detection via /proc/version and /proc/cpuinfo, user enumeration through /etc/passwd and /etc/shadow access attempts, environment variable inspection, history review, hostname identification, privilege level verification via id command, and disk/memory diagnostics. Test file writes to /tmp with epoch-based naming suggest capability validation. No malware downloads, persistence mechanisms, lateral movement attempts, or privilege escalation observed during sessions. Activity pattern consistent with automated scanning or initial access verification phase prior to potential payload deployment. Go SSH client implementation suggests infrastructure reconnaissance tooling rather than manual exploitation.
show less
Brute-Force
SSH
Anonymous
2026-09-01T14:32:11.657409+00:00 s158416 sshd[4035165]: Failed password for root from 161.248.37.160 ...
show more2026-09-01T14:32:11.657409+00:00 s158416 sshd[4035165]: Failed password for root from 161.248.37.160 port 46254 ssh2
2026-09-01T14:38:58.400869+00:00 s158416 sshd[4035698]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T14:39:00.060918+00:00 s158416 sshd[4035698]: Failed password for root from 161.248.37.160 port 41724 ssh2
2026-09-01T14:38:58.711739+00:00 s158416 sshd[4035700]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.248.37.160 user=root
2026-09-01T14:39:00.371374+00:00 s158416 sshd[4035700]: Failed password for root from 161.248.37.160 port 39640 ssh2
...
show less
Reconnaissance across 3 sessions using weak creds (root/123123qq, root/12321, root/123321). SSH-2.0- ...
show moreReconnaissance across 3 sessions using weak creds (root/123123qq, root/12321, root/123321). SSH-2.0-Go client indicates automated tooling, likely botnet scanner or brute-force framework. Attack chain: cred enumeration then system discovery. Recon cmds targeted OS fingerprinting (cat /etc/passwd, /etc/shadow, /proc/cpuinfo, /proc/version, hostname), env enumeration (env, history), privilege verification (id), writable dir validation (echo to /tmp). No malware dl, cmd injection, persistence, or lateral movement detected. 72 total cmd exec with 34 unique cmds suggests iterative probing of multiple targets or repeated cycling. Use of 2>/dev/null redirects indicates error suppression awareness, characteristic of scripted attacks. No suspicious binaries, scripts, or exploits observed. Activity consistent with recon phase of credential-stuffing campaign targeting default/weak SSH creds.
show less
conducted reconnaissance on compromised system using Go-based SSH client. Two successful authenticat ...
show moreconducted reconnaissance on compromised system using Go-based SSH client. Two successful authentication attempts using credential root/123123aa. Attack focused on host enumeration: extracted first line of /etc/passwd and /etc/shadow, queried CPU model, kernel version, environment variables, command history, and hostname. Created temporary test files in /tmp directory (test_1788271648, test_1788272074) to verify write permissions. Executed 35 unique commands across 70 total invocations during 7-minute window, indicating systematic information gathering. No malware downloads, persistence mechanisms, lateral movement attempts, or privilege escalation observed. Attack pattern consistent with initial reconnaissance phase of botnet infection or manual penetration testing. Weak credential (root/123123aa) suggests vulnerable target selection or credential harvesting from previous breach.
show less
Brute-Force
SSH
Showing 1 to
15
of 251 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ