This IP address has been reported a total of
20
times from
18 distinct
sources.
212.3.47.132 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 4
reports;
United States of America
with 4
reports;
Netherlands
with 2
reports.
The most common categories in these recent reports were:
Brute-Force
11
times;
SSH
8
times;
Web App Attack
1
time;
Exploited Host
1
time;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-10-05T13:39:26.756779+02:00 r2d2 sshd-session[326627]: Invalid user AdminGPON from 212.3.47.132 ...
show more2026-10-05T13:39:26.756779+02:00 r2d2 sshd-session[326627]: Invalid user AdminGPON from 212.3.47.132 port 44623
...
show less
Oct 4 11:44:31 gigabyte-h410m sshd[916814]: Invalid user admin from 212.3.47.132 port 38628
Oct 4 ...
show moreOct 4 11:44:31 gigabyte-h410m sshd[916814]: Invalid user admin from 212.3.47.132 port 38628
Oct 4 11:44:34 gigabyte-h410m sshd[916814]: Failed password for invalid user admin from 212.3.47.132 port 38628 ssh2
Oct 4 11:44:35 gigabyte-h410m sshd[916814]: Connection closed by invalid user admin 212.3.47.132 port 38628 [preauth]
...
show less
212.3.47.132 (ES/Spain/-), 5 distributed sshd attacks on account [admin] in the last 3600 secs; Port ...
show more212.3.47.132 (ES/Spain/-), 5 distributed sshd attacks on account [admin] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Sep 18 10:43:41 14474 sshd[30923]: Invalid user admin from 212.3.47.132 port 42169
Sep 18 10:43:42 14474 sshd[30923]: Failed password for invalid user admin from 212.3.47.132 port 42169 ssh2
Sep 18 10:13:44 14474 sshd[26100]: Invalid user admin from 87.26.135.52 port 30648
Sep 18 10:13:47 14474 sshd[26100]: Failed password for invalid user admin from 87.26.135.52 port 30648 ssh2
Sep 18 10:47:57 14474 sshd[31586]: Invalid user admin from 182.95.61.82 port 41646
IP Addresses Blocked:
show less
Automated honeypot observation: SSH brute-force / credential-stuffing. Failed logins: 1, successful: ...
show moreAutomated honeypot observation: SSH brute-force / credential-stuffing. Failed logins: 1, successful: 0, commands: 0, file transfers: 0. Seen on 1 sensor(s) (ch1) over 2026-09-18..2026-09-18. Reported by an SSH honeypot network; no production service involved.
show less
30 Jul 2026 04:36:23UTC:Distributed Brute Force Password Attack (smtp, ftp, imap, pop, ssh) includin ...
show more30 Jul 2026 04:36:23UTC:Distributed Brute Force Password Attack (smtp, ftp, imap, pop, ssh) including ip address 212.3.47.132
show less