This IP address has been reported a total of
61
times from
55 distinct
sources.
170.64.148.228 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
2026-03-12T02:30:45.309819-04:00 mail sshd[112462]: Failed password for root from 170.64.148.228 por ...
show more2026-03-12T02:30:45.309819-04:00 mail sshd[112462]: Failed password for root from 170.64.148.228 port 55352 ssh2
2026-03-12T02:32:37.236871-04:00 mail sshd[145902]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.64.148.228 user=root
2026-03-12T02:32:39.291803-04:00 mail sshd[145902]: Failed password for root from 170.64.148.228 port 50088 ssh2
2026-03-12T02:34:40.003596-04:00 mail sshd[181899]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.64.148.228 user=root
2026-03-12T02:34:41.806721-04:00 mail sshd[181899]: Failed password for root from 170.64.148.228 port 54100 ssh2
...
show less
2026-03-12T07:26:33.066458+01:00 karoxnet.hu sshd[1573954]: User root from 170.64.148.228 not allowe ...
show more2026-03-12T07:26:33.066458+01:00 karoxnet.hu sshd[1573954]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:28:35.111096+01:00 karoxnet.hu sshd[1573962]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:30:44.186550+01:00 karoxnet.hu sshd[1573969]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:32:37.554733+01:00 karoxnet.hu sshd[1573974]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:34:39.981875+01:00 karoxnet.hu sshd[1573982]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
...
show less
5 attempts since 12.03.2026 06:26:11 UTC - last one: 2026-03-12T07:34:19.390772+01:00 beta sshd-sess ...
show more5 attempts since 12.03.2026 06:26:11 UTC - last one: 2026-03-12T07:34:19.390772+01:00 beta sshd-session[3864232]: Connection closed by authenticating user root 170.64.148.228 port 40978 [preauth]
show less
Honeypot hit: Brute-force attack detected on 22/SSH
โข Credentials: root:root, root:admin, root:passw ...
show moreHoneypot hit: Brute-force attack detected on 22/SSH
โข Credentials: root:root, root:admin, root:password, root:123456
โข Number of login attempts: 4
โข 4 command(s) were executed during the session
โข Client: SSH-2.0-Go
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
2026-03-12T07:28:47.863157+01:00 servidor1 sshd[3989357]: User root from 170.64.148.228 not allowed ...
show more2026-03-12T07:28:47.863157+01:00 servidor1 sshd[3989357]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:28:48.521345+01:00 servidor1 sshd[3989357]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.64.148.228 user=root
2026-03-12T07:28:49.803630+01:00 servidor1 sshd[3989357]: Failed password for invalid user root from 170.64.148.228 port 58326 ssh2
2026-03-12T07:30:55.192892+01:00 servidor1 sshd[3991305]: User root from 170.64.148.228 not allowed because not listed in AllowUsers
2026-03-12T07:30:56.002469+01:00 servidor1 sshd[3991305]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.64.148.228 user=root
2026-03-12T07:30:58.052542+01:00 servidor1 sshd[3991305]: Failed password for invalid user root from 170.64.148.228 port 53844 ssh2
2026-03-12T07:32:48.685271+01:00 servidor1 sshd[3992125]: User root from 170.64.148.228 not allowed because not listed in Allo
...
show less
2026-03-12T07:23:44.395169+01:00 router01.dreibaeumen.de sshd[407020]: Connection closed by 170.64.1 ...
show more2026-03-12T07:23:44.395169+01:00 router01.dreibaeumen.de sshd[407020]: Connection closed by 170.64.148.228 port 46512
2026-03-12T07:26:18.904930+01:00 router01.dreibaeumen.de sshd[407468]: Connection closed by authenticating user root 170.64.148.228 port 38036 [preauth]
2026-03-12T07:28:21.408824+01:00 router01.dreibaeumen.de sshd[407741]: Connection closed by authenticating user root 170.64.148.228 port 36764 [preauth]
2026-03-12T07:30:30.210945+01:00 router01.dreibaeumen.de sshd[408047]: Connection closed by authenticating user root 170.64.148.228 port 60074 [preauth]
2026-03-12T07:32:25.187848+01:00 router01.dreibaeumen.de sshd[408304]: Connection closed by authenticating user root 170.64.148.228 port 36298 [preauth]
show less
2026-03-12T08:28:50.183487+02:00 mariusbm-MS-B90111 sshd[361493]: Failed password for root from 170. ...
show more2026-03-12T08:28:50.183487+02:00 mariusbm-MS-B90111 sshd[361493]: Failed password for root from 170.64.148.228 port 53296 ssh2
2026-03-12T08:30:58.603104+02:00 mariusbm-MS-B90111 sshd[362794]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=170.64.148.228 user=root
2026-03-12T08:31:00.065590+02:00 mariusbm-MS-B90111 sshd[362794]: Failed password for root from 170.64.148.228 port 55646 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 61 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ