This IP address has been reported a total of
31
times from
23 distinct
sources.
198.13.159.22 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 11
reports;
Germany
with 10
reports;
Finland
with 3
reports.
The most common categories in these recent reports were:
Port Scan
24
times;
Brute-Force
11
times;
SSH
5
times;
Hacking
4
times;
FTP Brute-Force
2
times;
Other
3
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
2026-09-28T08:16:13.574621+00:00 uptime-kuma-2604-b.us-west1-b.c.uptime-kuma-410917.internal sshd-se ...
show more2026-09-28T08:16:13.574621+00:00 uptime-kuma-2604-b.us-west1-b.c.uptime-kuma-410917.internal sshd-session[1543409]: error: kex_exchange_identification: read: Connection reset by peer
2026-09-28T08:16:13.574737+00:00 uptime-kuma-2604-b.us-west1-b.c.uptime-kuma-410917.internal sshd-session[1543409]: Connection reset by 198.13.159.22 port 60452
show less
Brute-Force
SSH
Anonymous
2026-09-27T20:13:25.942655+02:00 vps kernel: [6903596.457900] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more2026-09-27T20:13:25.942655+02:00 vps kernel: [6903596.457900] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=198.13.159.22 DST=54.37.14.118 LEN=60 TOS=0x00 PREC=0x00 TTL=48 ID=35544 DF PROTO=TCP SPT=41678 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Failed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 8/100 (info) ...
show moreFailed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 8/100 (info) | Phase: reconnaissance (pre-auth probing / scanning)
Failed auth: 0 (0 bad password, 0 invalid user) | 0 success | 10 total SSH log events | seen on 1 sensor(s)
Origin: The Netherlands (NL) | AS399629 BL Networks | 198.13.159.0/24
First seen: 2026-09-24 09:52:59 UTC | Last seen: 2026-09-27 08:43:40 UTC
Source: Linux OpenSSH journalctl telemetry, multi-sensor CERT honeypot.
show less
*Port Scan* detected from 198.13.159.22 (NL/The Netherlands/-). 11 hits in the last 282 seconds (0-1 ...
show more*Port Scan* detected from 198.13.159.22 (NL/The Netherlands/-). 11 hits in the last 282 seconds (0-195)
show less
Port Scan
Anonymous
2026-09-25T18:07:52.707184+02:00 vps kernel: [6723265.260759] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more2026-09-25T18:07:52.707184+02:00 vps kernel: [6723265.260759] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=198.13.159.22 DST=54.37.14.118 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=47711 DF PROTO=TCP SPT=51838 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
portscan on multiple TCP ports :
Firewall: Within 2026-09-22 06:44:26 - 2026-09-24 07:18:35 CEST(+02 ...
show moreportscan on multiple TCP ports :
Firewall: Within 2026-09-22 06:44:26 - 2026-09-24 07:18:35 CEST(+0200) identified: unallowed access from 198.13.159.22/32 on uncommon port/s: 2375(tcp:2375),6379(redis) (2 trials)
Fail2ban: Within 2026-09-22 06:44:26 - 2026-09-24 07:18:36 CEST(+0200) banned: 8 times by fail2ban[firewall]; 8 times by fail2ban[recidive]
show less
Port Scan
Anonymous
2026-09-23 18:09:00,674 fail2ban.actions [626]: NOTICE [endlessh] Ban 198.13.159.22
2026-09- ...
show more2026-09-23 18:09:00,674 fail2ban.actions [626]: NOTICE [endlessh] Ban 198.13.159.22
2026-09-24 20:17:29,756 fail2ban.actions [626]: NOTICE [endlessh] Ban 198.13.159.22
...
show less