This IP address has been reported a total of
31
times from
28 distinct
sources.
195.211.124.164 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 9
reports;
United States of America
with 7
reports;
France
with 3
reports.
The most common categories in these recent reports were:
SSH
26
times;
Brute-Force
18
times;
Port Scan
8
times;
Hacking
3
times;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot Finding: combined 2 reportable finding type(s) for this source IP; observed 2026-10-02T10:3 ...
show moreHoneypot Finding: combined 2 reportable finding type(s) for this source IP; observed 2026-10-02T10:32:51.560Z to 2026-10-02T11:35:46.737Z. Honeypot Finding: SSH intrusion activity on TCP/22; successful login, command, or download activity observed. | Honeypot Finding: repeated TCP service probing on TCP/22 (SSH); 5 application-level events across 5 source port(s). Sensor(s): Cowrie.
show less
Oct 2 13:31:50 box sshd-session[60959]: Connection closed by 195.211.124.164 port 57026 [preauth]
O ...
show moreOct 2 13:31:50 box sshd-session[60959]: Connection closed by 195.211.124.164 port 57026 [preauth]
Oct 2 13:33:04 box sshd-session[60970]: Connection closed by 195.211.124.164 port 46020 [preauth]
Oct 2 13:34:05 box sshd-session[60976]: Connection closed by 195.211.124.164 port 35370 [preauth]
Oct 2 13:34:23 box sshd-session[60978]: Connection closed by 195.211.124.164 port 33294 [preauth]
Oct 2 13:37:41 box sshd-session[61215]: Connection closed by 195.211.124.164 port 42706 [preauth]
...
show less
This IP address carried out 6 port scanning attempts on 01-10-2026. For more information or to repor ...
show moreThis IP address carried out 6 port scanning attempts on 01-10-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
2026-10-01T22:34:41.417635+02:00 v2202606371265473117 sshd-session[933961]: Invalid user admin from ...
show more2026-10-01T22:34:41.417635+02:00 v2202606371265473117 sshd-session[933961]: Invalid user admin from 195.211.124.164 port 44606
2026-10-01T22:34:41.480216+02:00 v2202606371265473117 sshd-session[933961]: Connection closed by invalid user admin 195.211.124.164 port 44606 [preauth]
2026-10-01T22:38:43.425493+02:00 v2202606371265473117 sshd-session[933969]: Invalid user admin from 195.211.124.164 port 48664
2026-10-01T22:38:43.452425+02:00 v2202606371265473117 sshd-session[933969]: Connection closed by invalid user admin 195.211.124.164 port 48664 [preauth]
2026-10-01T22:43:21.705297+02:00 v2202606371265473117 sshd-session[933979]: Invalid user Admin from 195.211.124.164 port 40296
...
show less
Brute-Force
SSH
Anonymous
SSH tarpit (endlessh) connection from 195.211.124.164
Cowrie SSH brute-force activity detected. 2 or more observation(s) from 2026-10-01T12:08:25.000Z thr ...
show moreCowrie SSH brute-force activity detected. 2 or more observation(s) from 2026-10-01T12:08:25.000Z through 2026-10-01T12:08:25.000Z.
show less
2026-10-01T15:28:02.315536+08:00 laxh2-202411170129435ddf18 sshd[1830553]: Invalid user pi from 195. ...
show more2026-10-01T15:28:02.315536+08:00 laxh2-202411170129435ddf18 sshd[1830553]: Invalid user pi from 195.211.124.164 port 38620
2026-10-01T15:28:02.478490+08:00 laxh2-202411170129435ddf18 sshd[1830553]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=195.211.124.164
2026-10-01T15:28:04.354660+08:00 laxh2-202411170129435ddf18 sshd[1830553]: Failed password for invalid user pi from 195.211.124.164 port 38620 ssh2
2026-10-01T15:37:09.608733+08:00 laxh2-202411170129435ddf18 sshd[1830566]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=195.211.124.164 user=root
2026-10-01T15:37:11.241891+08:00 laxh2-202411170129435ddf18 sshd[1830566]: Failed password for root from 195.211.124.164 port 39970 ssh2
...
show less
Dropbear: Bad password attempt.
Sep 30 21:36:32 *REDACTED* dropbear[16666]: Bad password attempt fo ...
show moreDropbear: Bad password attempt.
Sep 30 21:36:32 *REDACTED* dropbear[16666]: Bad password attempt for 'Admin' from 195.211.124.164:54500
show less
Honeypot detection: SSH/Telnet brute-force. 3 events observed. Reported automatically from a honeypo ...
show moreHoneypot detection: SSH/Telnet brute-force. 3 events observed. Reported automatically from a honeypot sensor.
show less