This IP address has been reported a total of
6,507
times from
1,302 distinct
sources.
197.248.207.139 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
SSH Honeypot attack.
2026-05-30T22:00:12Z{"client_version":"SSH-2.0-libssh_0.9.6","duser":"frappe"," ...
show moreSSH Honeypot attack.
2026-05-30T22:00:12Z{"client_version":"SSH-2.0-libssh_0.9.6","duser":"frappe","level":"info","msg":"Request with password","password":"123123","server_version":"SSH-2.0-OpenSSH_7.4","src":"197.248.207.139","time":"2026-05-31T03:33:16.727433158Z"}
2026-05-30T22:00:12Z{"client_version":"SSH-2.0-libssh_0.9.6","duser":"ldap","level":"info","msg":"Request with password","password":"ldap","server_version":"SSH-2.0-OpenSSH_7.4","src":"197.248.207.139","time":"2026-05-31T03:39:56.736750882Z"}
2026-05-30T22:00:12Z{"client_version":"SSH-2.0-libssh_0.9.6","duser":"root","level":"info","msg":"Request with password","password":",ki89ol.","server_version":"SSH-2.0-OpenSSH_7.4","src":"197.248.207.139","time":"2026-05-31T03:44:42.000687461Z"}
2026-05-30T22:00:12Z{"client_version":"SSH-2.0-libssh_0.9.6","duser":"dhis","level":"info","msg":"Request with password","password":"dhis","server_version":"SSH-2.0-OpenSSH_7.4","src":"197.248.207.139","time":"2026-05-31T03:46:24.217355874Z"}
2026-05-30T22:00:12
...
show less
2026-06-02T08:00:12.233659-06:00 vaako sshd[3428593]: Invalid user ca from 197.248.207.139 port 6457 ...
show more2026-06-02T08:00:12.233659-06:00 vaako sshd[3428593]: Invalid user ca from 197.248.207.139 port 64570
2026-06-02T08:00:12.239079-06:00 vaako sshd[3428593]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=197.248.207.139
2026-06-02T08:00:13.663448-06:00 vaako sshd[3428593]: Failed password for invalid user ca from 197.248.207.139 port 64570 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-06-02T12:48:39.423245 EUR sshd[17687]: Invalid user mohit from 197.248.207.139 port 36425
2026- ...
show more2026-06-02T12:48:39.423245 EUR sshd[17687]: Invalid user mohit from 197.248.207.139 port 36425
2026-06-02T12:55:33.177337 EUR sshd[19450]: Invalid user test from 197.248.207.139 port 3793
2026-06-02T12:59:04.119214 EUR sshd[20210]: Invalid user clawd from 197.248.207.139 port 20349
...
show less
2026-06-02T14:46:57.556970+02:00 axisverse sshd-session[554117]: Invalid user mohit from 197.248.207 ...
show more2026-06-02T14:46:57.556970+02:00 axisverse sshd-session[554117]: Invalid user mohit from 197.248.207.139 port 36056
2026-06-02T14:55:15.945575+02:00 axisverse sshd-session[568946]: Invalid user test from 197.248.207.139 port 10894
2026-06-02T14:58:49.215296+02:00 axisverse sshd-session[575561]: Invalid user clawd from 197.248.207.139 port 19920
...
show less
CSF/LFD blocked 197.248.207.139 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SS ...
show moreCSF/LFD blocked 197.248.207.139 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH login from 197.248.207.139 (KE/Kenya/197-248-207-139.safaricombusiness.co.ke): 5 in the last 3600 secs. Evidence: Jun 2 07:52:52 paladin sshd[595402]: Invalid user mohit from 197.248.207.139 port 14916
show less
Brute-Force
SSH
Anonymous
2026-06-02T14:40:34.487168 prodWEB sshd[45511]: Failed password for invalid user manager from 197.24 ...
show more2026-06-02T14:40:34.487168 prodWEB sshd[45511]: Failed password for invalid user manager from 197.248.207.139 port 17616 ssh2
2026-06-02T14:42:20.769328 prodWEB sshd[45540]: Connection from 197.248.207.139 port 13361 on 57.128.10.223 port 22 rdomain ""
2026-06-02T14:42:21.498075 prodWEB sshd[45540]: Invalid user admin from 197.248.207.139 port 13361
...
show less
Brute-Force
SSH
Anonymous
2026-06-02T14:17:04.446251 prodWEB sshd[45137]: Connection from 197.248.207.139 port 56945 on 57.128 ...
show more2026-06-02T14:17:04.446251 prodWEB sshd[45137]: Connection from 197.248.207.139 port 56945 on 57.128.10.223 port 22 rdomain ""
2026-06-02T14:17:05.201088 prodWEB sshd[45137]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=197.248.207.139 user=root
2026-06-02T14:17:07.258632 prodWEB sshd[45137]: Failed password for root from 197.248.207.139 port 56945 ssh2
...
show less
2026-06-02T07:52:06.441649-04:00 amadeus sshd-session[595685]: Invalid user stage from 197.248.207.1 ...
show more2026-06-02T07:52:06.441649-04:00 amadeus sshd-session[595685]: Invalid user stage from 197.248.207.139 port 63441
2026-06-02T07:57:25.273766-04:00 amadeus sshd-session[607073]: Connection from 197.248.207.139 port 49690 on 192.168.1.93 port 22 rdomain ""
2026-06-02T07:57:26.774031-04:00 amadeus sshd-session[607073]: Invalid user admin from 197.248.207.139 port 49690
...
show less
Brute-Force
SSH
Anonymous
2026-06-02T13:44:40.158330 prodWEB sshd[44655]: Failed password for invalid user valentina from 197. ...
show more2026-06-02T13:44:40.158330 prodWEB sshd[44655]: Failed password for invalid user valentina from 197.248.207.139 port 38442 ssh2
2026-06-02T13:52:04.130997 prodWEB sshd[44759]: Connection from 197.248.207.139 port 19422 on 57.128.10.223 port 22 rdomain ""
2026-06-02T13:52:04.859528 prodWEB sshd[44759]: Invalid user stage from 197.248.207.139 port 19422
...
show less
Brute-Force
SSH
Showing 106 to
120
of 6507 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ