This IP address has been reported a total of
191
times from
125 distinct
sources.
213.225.38.154 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
SSH brute force attempt. User: rmsadm, Pass: [REDACTED]
2026-06-04T02:35:40.559799+01:00 naomi sshd[103332]: pam_unix(sshd:auth): authentication failure; lo ...
show more2026-06-04T02:35:40.559799+01:00 naomi sshd[103332]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154
2026-06-04T02:35:42.726223+01:00 naomi sshd[103332]: Failed password for invalid user steam from 213.225.38.154 port 57357 ssh2
2026-06-04T02:35:44.479960+01:00 naomi sshd[103332]: Disconnected from invalid user steam 213.225.38.154 port 57357 [preauth]
...
show less
2026-06-04T03:19:23.999504+02:00 dev sshd[3727493]: pam_unix(sshd:auth): authentication failure; log ...
show more2026-06-04T03:19:23.999504+02:00 dev sshd[3727493]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
2026-06-04T03:19:25.709161+02:00 dev sshd[3727493]: Failed password for root from 213.225.38.154 port 50680 ssh2
2026-06-04T03:21:33.122280+02:00 dev sshd[3731435]: Invalid user ttuser from 213.225.38.154 port 50681
...
show less
2026-06-04T03:02:07.183211+02:00 axisverse sshd-session[1225198]: Invalid user mike from 213.225.38. ...
show more2026-06-04T03:02:07.183211+02:00 axisverse sshd-session[1225198]: Invalid user mike from 213.225.38.154 port 21680
2026-06-04T03:06:30.195182+02:00 axisverse sshd-session[1233565]: Invalid user kevin from 213.225.38.154 port 21683
2026-06-04T03:08:35.074656+02:00 axisverse sshd-session[1237656]: Invalid user stage from 213.225.38.154 port 21684
...
show less
Jun 3 17:46:20 koala sshd[1031309]: Invalid user vastbase from 213.225.38.154 port 31698
Jun 3 17: ...
show moreJun 3 17:46:20 koala sshd[1031309]: Invalid user vastbase from 213.225.38.154 port 31698
Jun 3 17:55:04 koala sshd[1031421]: Invalid user newuser from 213.225.38.154 port 31700
...
show less
2026-06-04T02:47:54.179145+02:00 dev sshd[3666452]: Failed password for invalid user vastbase from 2 ...
show more2026-06-04T02:47:54.179145+02:00 dev sshd[3666452]: Failed password for invalid user vastbase from 213.225.38.154 port 50666 ssh2
2026-06-04T02:53:20.376366+02:00 dev sshd[3678156]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
2026-06-04T02:53:21.845442+02:00 dev sshd[3678156]: Failed password for root from 213.225.38.154 port 50667 ssh2
...
show less
2026-06-04T01:26:21.874981+02:00 gw9.nodesafety.com sshd-session[239590]: Invalid user marcelo from ...
show more2026-06-04T01:26:21.874981+02:00 gw9.nodesafety.com sshd-session[239590]: Invalid user marcelo from 213.225.38.154 port 30617
2026-06-04T01:26:21.953546+02:00 gw9.nodesafety.com sshd-session[239590]: Disconnected from invalid user marcelo 213.225.38.154 port 30617 [preauth]
2026-06-04T01:31:33.702456+02:00 gw9.nodesafety.com sshd-session[240405]: Invalid user hik from 213.225.38.154 port 30619
2026-06-04T01:31:33.787379+02:00 gw9.nodesafety.com sshd-session[240405]: Disconnected from invalid user hik 213.225.38.154 port 30619 [preauth]
2026-06-04T01:33:36.705011+02:00 gw9.nodesafety.com sshd-session[240716]: Invalid user ftp from 213.225.38.154 port 30620
show less
2026-06-03T17:23:09.046985-06:00 derp sshd-session[254480]: Invalid user marcelo from 213.225.38.154 ...
show more2026-06-03T17:23:09.046985-06:00 derp sshd-session[254480]: Invalid user marcelo from 213.225.38.154 port 50691
2026-06-03T17:31:07.040174-06:00 derp sshd-session[254503]: Invalid user hik from 213.225.38.154 port 50692
2026-06-03T17:33:06.074260-06:00 derp sshd-session[254508]: Invalid user ftp from 213.225.38.154 port 50693
...
show less
2026-06-04T09:00:40.078231+10:00 sleep-salami sshd[899143]: Invalid user deploy from 213.225.38.154 ...
show more2026-06-04T09:00:40.078231+10:00 sleep-salami sshd[899143]: Invalid user deploy from 213.225.38.154 port 33977
2026-06-04T09:00:40.370335+10:00 sleep-salami sshd[899143]: Disconnected from invalid user deploy 213.225.38.154 port 33977 [preauth]
2026-06-04T09:02:49.895201+10:00 sleep-salami sshd[899273]: Disconnected from authenticating user root 213.225.38.154 port 35032 [preauth]
2026-06-04T09:04:59.304766+10:00 sleep-salami sshd[899349]: Disconnected from authenticating user root 213.225.38.154 port 35034 [preauth]
2026-06-04T09:07:00.491644+10:00 sleep-salami sshd[899408]: Disconnected from authenticating user root 213.225.38.154 port 35035 [preauth]
...
show less
2026-06-04T08:45:36.827756+10:00 sleep-salami sshd[898268]: Invalid user postgres from 213.225.38.15 ...
show more2026-06-04T08:45:36.827756+10:00 sleep-salami sshd[898268]: Invalid user postgres from 213.225.38.154 port 33969
2026-06-04T08:45:37.128386+10:00 sleep-salami sshd[898268]: Disconnected from invalid user postgres 213.225.38.154 port 33969 [preauth]
2026-06-04T08:47:40.530539+10:00 sleep-salami sshd[898422]: Invalid user whs from 213.225.38.154 port 33971
2026-06-04T08:47:40.821180+10:00 sleep-salami sshd[898422]: Disconnected from invalid user whs 213.225.38.154 port 33971 [preauth]
2026-06-04T08:49:50.053107+10:00 sleep-salami sshd[898588]: Invalid user ubuntu from 213.225.38.154 port 33972
...
show less
2026-06-04T08:29:26.989356+10:00 sleep-salami sshd[897130]: Invalid user qwerty from 213.225.38.154 ...
show more2026-06-04T08:29:26.989356+10:00 sleep-salami sshd[897130]: Invalid user qwerty from 213.225.38.154 port 33961
2026-06-04T08:29:27.281919+10:00 sleep-salami sshd[897130]: Disconnected from invalid user qwerty 213.225.38.154 port 33961 [preauth]
2026-06-04T08:31:34.225483+10:00 sleep-salami sshd[897371]: Disconnected from authenticating user root 213.225.38.154 port 33962 [preauth]
2026-06-04T08:34:45.720304+10:00 sleep-salami sshd[897684]: Invalid user ernawati from 213.225.38.154 port 33964
2026-06-04T08:34:46.020517+10:00 sleep-salami sshd[897684]: Disconnected from invalid user ernawati 213.225.38.154 port 33964 [preauth]
...
show less
Brute-Force
SSH
Showing 1 to
15
of 191 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ