Apr 5 01:27:49 mail sshd[4001]: Failed password for root from 209.38.95.244 port 39830 ssh2
Apr 5 ...
show moreApr 5 01:27:49 mail sshd[4001]: Failed password for root from 209.38.95.244 port 39830 ssh2
Apr 5 01:29:56 mail sshd[4030]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=209.38.95.244
Apr 5 01:29:58 mail sshd[4030]: Failed password for invalid user mauro from 209.38.95.244 port 58380 ssh2
Apr 5 01:30:18 mail sshd[4033]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=209.38.95.244
Apr 5 01:30:19 mail sshd[4033]: Failed password for invalid user a1marion from 209.38.95.244 port 54398 ssh2
Apr 5 01:30:28 mail sshd[4374]: Failed password for root from 209.38.95.244 port 41552 ssh2
...
show less
2026-04-05T02:27:43.077762+03:00 oh6ah sshd[1486115]: Failed password for root from 209.38.95.244 po ...
show more2026-04-05T02:27:43.077762+03:00 oh6ah sshd[1486115]: Failed password for root from 209.38.95.244 port 41784 ssh2
2026-04-05T02:29:54.407853+03:00 oh6ah sshd[1486757]: Invalid user mauro from 209.38.95.244 port 35366
...
show less
[Sun Apr 5 01:27:24 AM CEST 2026] [Automated Fail2Ban Report] Unauthorized attempt to connect via S ...
show more[Sun Apr 5 01:27:24 AM CEST 2026] [Automated Fail2Ban Report] Unauthorized attempt to connect via SSH
show less
Malicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: ...
show moreMalicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: AS14061 DigitalOcean, LLC, Region: New South Wales, Log: 2026-03-10T16:43:50.287691 01:00 Administracion sshd[744463]: Connection closed by authenticating user root 209.38.95.244 port 60392 [preauth], Abuse Score: 100, Total Reports: 20
show less
2026-03-10T23:38:44.296785+08:00 dh sshd[1320663]: Connection closed by authenticating user root 209 ...
show more2026-03-10T23:38:44.296785+08:00 dh sshd[1320663]: Connection closed by authenticating user root 209.38.95.244 port 60026 [preauth]
2026-03-10T23:40:09.289203+08:00 dh sshd[1320853]: Connection closed by authenticating user root 209.38.95.244 port 50136 [preauth]
2026-03-10T23:41:23.291584+08:00 dh sshd[1320991]: Connection closed by authenticating user root 209.38.95.244 port 55924 [preauth]
2026-03-10T23:42:32.789251+08:00 dh sshd[1321100]: Connection closed by authenticating user root 209.38.95.244 port 48858 [preauth]
2026-03-10T23:43:40.159745+08:00 dh sshd[1321164]: Connection closed by authenticating user root 209.38.95.244 port 39102 [preauth]
show less
Brute-Force
SSH
Showing 1 to
15
of 34 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ