This IP address has been reported a total of
429
times from
274 distinct
sources.
170.130.201.42 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
SSH brute force attempt. User: test, Pass: [REDACTED]
Blocked by UFW (TCP on 23)
Source port: 35691
TTL: 52
Packet length: 40
TOS: 0x08
This report (for ...
show moreBlocked by UFW (TCP on 23)
Source port: 35691
TTL: 52
Packet length: 40
TOS: 0x08
This report (for 170.130.201.42) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
2026-05-20T09:07:48.307731+02:00 server1 sshd-session[4020048]: Invalid user admin from 170.130.201. ...
show more2026-05-20T09:07:48.307731+02:00 server1 sshd-session[4020048]: Invalid user admin from 170.130.201.42 port 42470
2026-05-20T09:08:19.367340+02:00 server1 sshd-session[4020424]: Invalid user orangepi from 170.130.201.42 port 34084
2026-05-20T09:08:51.751340+02:00 server1 sshd-session[4020693]: User root from 170.130.201.42 not allowed because not listed in AllowUsers
...
show less
2026-05-20T06:57:38.177636+00:00 edge-zap-akl01.int.pdx.net.uk sshd-session[1596254]: Invalid user a ...
show more2026-05-20T06:57:38.177636+00:00 edge-zap-akl01.int.pdx.net.uk sshd-session[1596254]: Invalid user admin from 170.130.201.42 port 39240
2026-05-20T06:58:09.268826+00:00 edge-zap-akl01.int.pdx.net.uk sshd-session[1596301]: Invalid user orangepi from 170.130.201.42 port 59474
2026-05-20T07:01:47.338601+00:00 edge-zap-akl01.int.pdx.net.uk sshd-session[1596617]: Invalid user test from 170.130.201.42 port 33466
...
show less
2026-05-20T08:53:07.541106+02:00 gw-de35-01.guestgw.net sshd[788035]: Connection closed by authentic ...
show more2026-05-20T08:53:07.541106+02:00 gw-de35-01.guestgw.net sshd[788035]: Connection closed by authenticating user admin 170.130.201.42 port 41488 [preauth]
2026-05-20T08:53:38.328289+02:00 gw-de35-01.guestgw.net sshd[788155]: Invalid user orangepi from 170.130.201.42 port 57486
2026-05-20T08:53:38.623101+02:00 gw-de35-01.guestgw.net sshd[788155]: Connection closed by invalid user orangepi 170.130.201.42 port 57486 [preauth]
2026-05-20T08:54:09.516749+02:00 gw-de35-01.guestgw.net sshd[788326]: Connection closed by authenticating user root 170.130.201.42 port 44268 [preauth]
2026-05-20T08:54:40.546277+02:00 gw-de35-01.guestgw.net sshd[788447]: Connection closed by authenticating user root 170.130.201.42 port 34334 [preauth]
show less
Attempted to exploit CVE-2017-9841 (PHPUnit RCE) by requesting /vendor/phpunit/phpunit/src/Util/PHP/ ...
show moreAttempted to exploit CVE-2017-9841 (PHPUnit RCE) by requesting /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php.
show less
Web App Attack
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
2026-05-20T09:25:37.081838+03:00 sabrina sshd[1537397]: Invalid user admin from 170.130.201.42 port ...
show more2026-05-20T09:25:37.081838+03:00 sabrina sshd[1537397]: Invalid user admin from 170.130.201.42 port 50968
2026-05-20T09:26:08.109072+03:00 sabrina sshd[1537427]: Invalid user orangepi from 170.130.201.42 port 47856
2026-05-20T09:29:45.035133+03:00 sabrina sshd[1537667]: Invalid user test from 170.130.201.42 port 48290
...
show less
[Fail2Ban] Banned 170.130.201.42 for 600 seconds. Relevant log lines: 2026-05-20T13:27:53&170728+07: ...
show more[Fail2Ban] Banned 170.130.201.42 for 600 seconds. Relevant log lines: 2026-05-20T13:27:53&170728+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186383&: Invalid user admin from 170&130&201&42 port 53834 2026-05-20T13:27:53&929746+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186383&: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170&130&201&42 2026-05-20T13:27:55&870329+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186383&: Failed password for invalid user admin from 170&130&201&42 port 53834 ssh2 2026-05-20T13:28:32&880787+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186431&: Invalid user orangepi from 170&130&201&42 port 60790 2026-05-20T13:28:32&910884+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186431&: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170&130&201&42 2026-05-20T13:28:35&865372+07:00 iZk1a2l3gukhtm6gic2ky3Z sshd&186431&: Failed password for invalid user orangepi from 170&130&201&42 port 60790 ssh2
show less
(sshd) Failed SSH login from 170.130.201.42 (US/United States/fileagi.com): 5 in the last 3600 secs; ...
show more(sshd) Failed SSH login from 170.130.201.42 (US/United States/fileagi.com): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: May 20 01:26:04 15448 sshd[848]: Invalid user admin from 170.130.201.42 port 33686
May 20 01:26:06 15448 sshd[848]: Failed password for invalid user admin from 170.130.201.42 port 33686 ssh2
May 20 01:26:36 15448 sshd[893]: Invalid user orangepi from 170.130.201.42 port 35772
May 20 01:26:39 15448 sshd[893]: Failed password for invalid user orangepi from 170.130.201.42 port 35772 ssh2
May 20 01:27:09 15448 sshd[1004]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.130.201.42 user=root
show less
2026-05-20T06:25:40.541768+00:00 alertalicitacao sshd[158984]: User root from 170.130.201.42 not all ...
show more2026-05-20T06:25:40.541768+00:00 alertalicitacao sshd[158984]: User root from 170.130.201.42 not allowed because not listed in AllowUsers
2026-05-20T06:26:10.863288+00:00 alertalicitacao sshd[159005]: Connection from 170.130.201.42 port 46540 on 192.168.100.167 port 22 rdomain ""
2026-05-20T06:26:11.498471+00:00 alertalicitacao sshd[159005]: User root from 170.130.201.42 not allowed because not listed in AllowUsers
2026-05-20T06:26:41.819868+00:00 alertalicitacao sshd[159018]: Connection from 170.130.201.42 port 45472 on 192.168.100.167 port 22 rdomain ""
2026-05-20T06:26:42.455415+00:00 alertalicitacao sshd[159018]: User root from 170.130.201.42 not allowed because not listed in AllowUsers
...
show less