UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show moreUFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=209.38.98.240; proto=TCP; source_port=61003; target_port=5552; flags=SYN
show less
Blocked by UFW (TCP on 1224)
Source port: 61006
TTL: 236
Packet length: 44
TOS: 0x08
This report (f ...
show moreBlocked by UFW (TCP on 1224)
Source port: 61006
TTL: 236
Packet length: 44
TOS: 0x08
This report (for 209.38.98.240) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Mar 9 07:21:40 VPS sshd[163040]: User root from 209.38.98.240 not allowed because not listed in All ...
show moreMar 9 07:21:40 VPS sshd[163040]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
Mar 9 07:21:40 VPS sshd[163040]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=209.38.98.240 user=root
Mar 9 07:21:40 VPS sshd[163040]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
Mar 9 07:21:42 VPS sshd[163040]: Failed password for invalid user root from 209.38.98.240 port 58460 ssh2
Mar 9 07:22:20 VPS sshd[163065]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
...
show less
Mar 9 06:57:59 VPS sshd[159998]: User root from 209.38.98.240 not allowed because not listed in All ...
show moreMar 9 06:57:59 VPS sshd[159998]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
Mar 9 06:57:59 VPS sshd[159998]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=209.38.98.240 user=root
Mar 9 06:57:59 VPS sshd[159998]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
Mar 9 06:58:01 VPS sshd[159998]: Failed password for invalid user root from 209.38.98.240 port 46986 ssh2
Mar 9 06:58:44 VPS sshd[160051]: User root from 209.38.98.240 not allowed because not listed in AllowUsers
...
show less
Malicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: ...
show moreMalicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: AS14061 DigitalOcean, LLC, Region: North Holland, Log: 2026-03-09T07:36:19.838514 01:00 Administracion sshd[484905]: Connection closed by authenticating user root 209.38.98.240 port 53280 [preauth], Abuse Score: 98, Total Reports: 20
show less
2026-03-09T06:34:23.291655+00:00 ubuntu sshd[470795]: Failed password for root from 209.38.98.240 po ...
show more2026-03-09T06:34:23.291655+00:00 ubuntu sshd[470795]: Failed password for root from 209.38.98.240 port 56302 ssh2
2026-03-09T06:35:18.923606+00:00 ubuntu sshd[470805]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=209.38.98.240 user=root
2026-03-09T06:35:20.769410+00:00 ubuntu sshd[470805]: Failed password for root from 209.38.98.240 port 44894 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 35 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ