Detected SSH brute force attack from 3 different servers
SSH
Brute-Force
Anonymous
This IP was detected by CrowdSec triggering crowdsecurity/ssh-slow-bf. Ip: 161.35.76.203 - ASN: 1406 ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/ssh-slow-bf. Ip: 161.35.76.203 - ASN: 14061 (DIGITALOCEAN-ASN) - Maliciousness Score is 10 %
show less
Mar 2 06:53:19 LYN-1 sshd[3584500]: Failed password for root from 161.35.76.203 port 47630 ssh2
Mar ...
show moreMar 2 06:53:19 LYN-1 sshd[3584500]: Failed password for root from 161.35.76.203 port 47630 ssh2
Mar 2 06:53:58 LYN-1 sshd[3584503]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.35.76.203 user=root
Mar 2 06:54:00 LYN-1 sshd[3584503]: Failed password for root from 161.35.76.203 port 51800 ssh2
Mar 2 06:54:37 LYN-1 sshd[3584518]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.35.76.203 user=root
Mar 2 06:54:38 LYN-1 sshd[3584518]: Failed password for root from 161.35.76.203 port 60484 ssh2
...
show less
2026-03-02T06:51:01.858863+00:00 api sshd[28042]: Connection closed by 161.35.76.203 port 48152
2026 ...
show more2026-03-02T06:51:01.858863+00:00 api sshd[28042]: Connection closed by 161.35.76.203 port 48152
2026-03-02T06:51:51.364745+00:00 api sshd[28055]: Connection closed by authenticating user root 161.35.76.203 port 48782 [preauth]
2026-03-02T06:52:31.296042+00:00 api sshd[28061]: Connection closed by authenticating user root 161.35.76.203 port 38726 [preauth]
2026-03-02T06:53:13.040388+00:00 api sshd[28070]: Connection closed by authenticating user root 161.35.76.203 port 60394 [preauth]
2026-03-02T06:53:54.491728+00:00 api sshd[28075]: Connection closed by authenticating user root 161.35.76.203 port 55264 [preauth]
...
show less
2026-03-02T08:53:04.093670+02:00 Vless sshd-session[806590]: Failed password for root from 161.35.76 ...
show more2026-03-02T08:53:04.093670+02:00 Vless sshd-session[806590]: Failed password for root from 161.35.76.203 port 41638 ssh2
2026-03-02T08:53:43.858615+02:00 Vless sshd-session[806595]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=161.35.76.203 user=root
2026-03-02T08:53:45.514265+02:00 Vless sshd-session[806595]: Failed password for root from 161.35.76.203 port 58912 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 57 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ