This IP address has been reported a total of
658
times from
374 distinct
sources.
201.138.189.215 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: botuser, Pass: [REDACTED]
Jun 1 09:58:29 b146-65 sshd[357223]: pam_unix(sshd:auth): authentication failure; logname= uid=0 eu ...
show moreJun 1 09:58:29 b146-65 sshd[357223]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215 user=root
Jun 1 09:58:31 b146-65 sshd[357223]: Failed password for root from 201.138.189.215 port 41718 ssh2
Jun 1 10:00:05 b146-65 sshd[357251]: Invalid user erfan from 201.138.189.215 port 56894
...
show less
Jun 1 15:58:24 jump sshd[2313166]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid ...
show moreJun 1 15:58:24 jump sshd[2313166]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215 user=root
Jun 1 15:58:25 jump sshd[2313166]: Failed password for root from 201.138.189.215 port 34952 ssh2
Jun 1 15:59:59 jump sshd[2313210]: Invalid user erfan from 201.138.189.215 port 45256
...
show less
2026-06-01T08:33:21.020350-07:00 server.vexstria.pro sshd[3121379]: pam_unix(sshd:auth): authenticat ...
show more2026-06-01T08:33:21.020350-07:00 server.vexstria.pro sshd[3121379]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215 user=root
2026-06-01T08:33:23.030843-07:00 server.vexstria.pro sshd[3121379]: Failed password for root from 201.138.189.215 port 35052 ssh2
2026-06-01T08:34:57.377453-07:00 server.vexstria.pro sshd[3151822]: Invalid user admin from 201.138.189.215 port 49898
...
show less
Brute-Force
SSH
Port Scan
FTP Brute-Force
Anonymous
Jun 1 11:22:08 v sshd\[29690\]: pam_unix\(sshd:auth\): authentication failure\; logname= uid=0 euid ...
show moreJun 1 11:22:08 v sshd\[29690\]: pam_unix\(sshd:auth\): authentication failure\; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215 user=root
Jun 1 11:22:10 v sshd\[29690\]: Failed password for root from 201.138.189.215 port 49640 ssh2
Jun 1 11:32:08 v sshd\[30304\]: pam_unix\(sshd:auth\): authentication failure\; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215 user=root
...
show less
2026-06-01T15:06:10.753117+00:00 boron.billy.wales sshd-session[3234971]: Invalid user dennis from 2 ...
show more2026-06-01T15:06:10.753117+00:00 boron.billy.wales sshd-session[3234971]: Invalid user dennis from 201.138.189.215 port 52772
2026-06-01T15:10:32.417501+00:00 boron.billy.wales sshd-session[3235498]: Invalid user axel from 201.138.189.215 port 35090
2026-06-01T15:11:58.451884+00:00 boron.billy.wales sshd-session[3235647]: Invalid user mark from 201.138.189.215 port 50264
2026-06-01T15:15:02.300913+00:00 boron.billy.wales sshd-session[3236242]: Invalid user george from 201.138.189.215 port 52588
2026-06-01T15:16:36.446741+00:00 boron.billy.wales sshd-session[3236404]: Invalid user iptv from 201.138.189.215 port 50434
...
show less
Jun 1 16:58:16 dev0-dcde-rnet sshd[13057]: pam_unix(sshd:auth): authentication failure; logname= ui ...
show moreJun 1 16:58:16 dev0-dcde-rnet sshd[13057]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.138.189.215
Jun 1 16:58:17 dev0-dcde-rnet sshd[13057]: Failed password for invalid user d from 201.138.189.215 port 60250 ssh2
Jun 1 17:00:40 dev0-dcde-rnet sshd[13094]: Failed password for root from 201.138.189.215 port 35606 ssh2
show less
2026-06-01T16:32:19.687430+03:00 zver.local sshd[2762]: Invalid user oracle from 201.138.189.215 por ...
show more2026-06-01T16:32:19.687430+03:00 zver.local sshd[2762]: Invalid user oracle from 201.138.189.215 port 53182
2026-06-01T16:35:27.663725+03:00 zver.local sshd[2795]: Invalid user stefan from 201.138.189.215 port 33370
2026-06-01T16:38:16.104331+03:00 zver.local sshd[2827]: Invalid user administrador from 201.138.189.215 port 40496
2026-06-01T16:41:10.596034+03:00 zver.local sshd[2850]: Invalid user shalini from 201.138.189.215 port 60590
...
show less
Brute-Force
SSH
Showing 196 to
210
of 658 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ