This IP address has been reported a total of
202
times from
132 distinct
sources.
213.225.38.154 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Repeated SSH brute force and user enumeration attempts against a secured server. Multiple failed aut ...
show moreRepeated SSH brute force and user enumeration attempts against a secured server. Multiple failed authentication attempts from this IP across an extended period.
show less
Brute-Force
SSH
Anonymous
2026-06-02T11:37:40.825775+03:00 knotty-cookie sshd[173618]: Invalid user dev from 213.225.38.154 po ...
show more2026-06-02T11:37:40.825775+03:00 knotty-cookie sshd[173618]: Invalid user dev from 213.225.38.154 port 55150
2026-06-02T11:41:19.019076+03:00 knotty-cookie sshd[173640]: Invalid user abrar from 213.225.38.154 port 55152
2026-06-02T11:43:11.291676+03:00 knotty-cookie sshd[173648]: Invalid user dolphin from 213.225.38.154 port 55153
2026-06-02T11:45:05.978024+03:00 knotty-cookie sshd[173660]: Invalid user en from 213.225.38.154 port 55154
2026-06-02T11:47:03.853362+03:00 knotty-cookie sshd[173666]: Invalid user freelancer from 213.225.38.154 port 55155
...
show less
2026-06-02T10:37:08.772680+02:00 rev-crew.info sshd-session[434261]: Connection from 213.225.38.154 ...
show more2026-06-02T10:37:08.772680+02:00 rev-crew.info sshd-session[434261]: Connection from 213.225.38.154 port 33962 on 5.9.102.122 port 2244 rdomain ""
2026-06-02T10:37:09.077940+02:00 rev-crew.info sshd-session[434261]: Invalid user dev from 213.225.38.154 port 33962
2026-06-02T10:37:09.118841+02:00 rev-crew.info sshd-session[434261]: Disconnected from invalid user dev 213.225.38.154 port 33962 [preauth]
2026-06-02T10:39:01.378926+02:00 rev-crew.info sshd-session[436649]: Disconnected from authenticating user root 213.225.38.154 port 33964 [preauth]
2026-06-02T10:40:49.533447+02:00 rev-crew.info sshd-session[439026]: Connection from 213.225.38.154 port 33965 on 5.9.102.122 port 2244 rdomain ""
2026-06-02T10:40:49.816951+02:00 rev-crew.info sshd-session[439026]: Invalid user abrar from 213.225.38.154 port 33965
...
show less
(sshd) Failed SSH login from 213.225.38.154 (AT/Austria/213-225-38-154.nat.highway.a1.net): 5 in the ...
show more(sshd) Failed SSH login from 213.225.38.154 (AT/Austria/213-225-38-154.nat.highway.a1.net): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 2 03:32:22 14415 sshd[5776]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
Jun 2 03:32:23 14415 sshd[5776]: Failed password for root from 213.225.38.154 port 19440 ssh2
Jun 2 03:35:57 14415 sshd[6122]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
Jun 2 03:35:59 14415 sshd[6122]: Failed password for root from 213.225.38.154 port 19441 ssh2
Jun 2 03:37:46 14415 sshd[6335]: Invalid user dev from 213.225.38.154 port 19442
show less
2026-06-02T09:24:40.647127+01:00 CiviDrupal16GB sshd[617022]: User root from 213.225.38.154 not allo ...
show more2026-06-02T09:24:40.647127+01:00 CiviDrupal16GB sshd[617022]: User root from 213.225.38.154 not allowed because not listed in AllowUsers
2026-06-02T09:34:45.169807+01:00 CiviDrupal16GB sshd[617244]: User root from 213.225.38.154 not allowed because not listed in AllowUsers
...
show less
2026-06-02T09:49:50.909997+02:00 v30393 sshd[1859418]: Invalid user es from 213.225.38.154 port 5738 ...
show more2026-06-02T09:49:50.909997+02:00 v30393 sshd[1859418]: Invalid user es from 213.225.38.154 port 57386
2026-06-02T09:49:50.964321+02:00 v30393 sshd[1859418]: Disconnected from invalid user es 213.225.38.154 port 57386 [preauth]
...
show less
2026-06-02T07:24:50.012138+00:00 Door-Opener-Proxy sshd[681834]: Invalid user admin from 213.225.38. ...
show more2026-06-02T07:24:50.012138+00:00 Door-Opener-Proxy sshd[681834]: Invalid user admin from 213.225.38.154 port 11653
2026-06-02T07:24:50.016377+00:00 Door-Opener-Proxy sshd[681834]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154
2026-06-02T07:24:51.489333+00:00 Door-Opener-Proxy sshd[681834]: Failed password for invalid user admin from 213.225.38.154 port 11653 ssh2
2026-06-02T07:26:48.545614+00:00 Door-Opener-Proxy sshd[683504]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
2026-06-02T07:26:50.885859+00:00 Door-Opener-Proxy sshd[683504]: Failed password for root from 213.225.38.154 port 11655 ssh2
...
show less
2026-06-02T07:09:00.170628+00:00 Door-Opener-Proxy sshd[669271]: Invalid user tux from 213.225.38.15 ...
show more2026-06-02T07:09:00.170628+00:00 Door-Opener-Proxy sshd[669271]: Invalid user tux from 213.225.38.154 port 11642
2026-06-02T07:09:00.174500+00:00 Door-Opener-Proxy sshd[669271]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154
2026-06-02T07:09:01.897875+00:00 Door-Opener-Proxy sshd[669271]: Failed password for invalid user tux from 213.225.38.154 port 11642 ssh2
2026-06-02T07:10:57.248430+00:00 Door-Opener-Proxy sshd[670923]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
2026-06-02T07:10:59.032910+00:00 Door-Opener-Proxy sshd[670923]: Failed password for root from 213.225.38.154 port 11643 ssh2
...
show less
2026-06-02T08:49:34.902396+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224480]: Invalid user sy ...
show more2026-06-02T08:49:34.902396+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224480]: Invalid user syp from 213.225.38.154 port 16064
2026-06-02T08:53:11.748258+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224582]: Invalid user bit from 213.225.38.154 port 16067
2026-06-02T08:55:01.685086+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224646]: Invalid user admin from 213.225.38.154 port 16068
2026-06-02T08:56:56.029403+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224723]: Invalid user ionela from 213.225.38.154 port 16069
2026-06-02T08:58:55.860189+02:00 c8ad96d3-a03b-4047-9371-ea18a81dda80 sshd[1224776]: Invalid user supports from 213.225.38.154 port 16071
...
show less
2026-06-02T08:49:24.370765+02:00 [server] sshd-session[4131102]: Invalid user syp from 213.225.38.15 ...
show more2026-06-02T08:49:24.370765+02:00 [server] sshd-session[4131102]: Invalid user syp from 213.225.38.154 port 20567
2026-06-02T08:53:01.257544+02:00 [server] sshd-session[4131879]: Invalid user bit from 213.225.38.154 port 20569
2026-06-02T08:54:51.161123+02:00 [server] sshd-session[4132191]: Invalid user admin from 213.225.38.154 port 20570
...
show less
2026-06-02T06:51:21.025996+00:00 Door-Opener-Proxy sshd[654177]: pam_unix(sshd:auth): authentication ...
show more2026-06-02T06:51:21.025996+00:00 Door-Opener-Proxy sshd[654177]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154 user=root
2026-06-02T06:51:23.230174+00:00 Door-Opener-Proxy sshd[654177]: Failed password for root from 213.225.38.154 port 11631 ssh2
2026-06-02T06:53:13.706915+00:00 Door-Opener-Proxy sshd[655856]: Invalid user bit from 213.225.38.154 port 11632
2026-06-02T06:53:13.709979+00:00 Door-Opener-Proxy sshd[655856]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.225.38.154
2026-06-02T06:53:15.428308+00:00 Door-Opener-Proxy sshd[655856]: Failed password for invalid user bit from 213.225.38.154 port 11632 ssh2
...
show less
Brute-Force
SSH
Showing 181 to
195
of 202 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ