AbuseIPDB » 219.145.111.197
219.145.111.197 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 13% : ?
ISP
CHINANET shanxi(SN) province network
Usage Type
Fixed Line ISP
ASN
AS4134
Domain Name
xa.sn.cn
Country
π¨π³
China
City
Xi'an, Shaanxi
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 219.145.111.197 :
This IP address has been reported a total of
4
times from
4 distinct
sources.
219.145.111.197 was first reported on
September 22nd 2022 , and the most recent report was
9 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π©πͺ
LoNET
2026-06-22 17:35:44
(9 hours ago)
Report 2491502 with IP 3539069 for SSH brute-force attack by source 3533727 via ssh-honeypot/0.2.0+h ...
show more
Report 2491502 with IP 3539069 for SSH brute-force attack by source 3533727 via ssh-honeypot/0.2.0+http
show less
Brute-Force
SSH
π°π·
Woodie
2026-05-29 00:34:20
(3 weeks ago)
2026-05-28T20:34:17.651924-04:00 debian sshd[3253174]: Failed password for root from 219.145.111.197 ...
show more
2026-05-28T20:34:17.651924-04:00 debian sshd[3253174]: Failed password for root from 219.145.111.197 port 59098 ssh2
2026-05-28T20:34:15.955471-04:00 debian sshd[3253133]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=219.145.111.197 user=root
2026-05-28T20:34:17.943907-04:00 debian sshd[3253133]: Failed password for root from 219.145.111.197 port 44758 ssh2
2026-05-28T20:34:16.774825-04:00 debian sshd[3253227]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=219.145.111.197 user=root
2026-05-28T20:34:18.568239-04:00 debian sshd[3253227]: Failed password for root from 219.145.111.197 port 40316 ssh2
...
show less
Brute-Force
SSH
πΈπ¬
bioxten.com
2022-10-30 17:40:23
(3 years ago)
219.145.111.197 (CN/China/Shanxi/Fenyang/-/[AS4134 CHINANET-BACKBONE No.31,Jin-rong Street]), 5 dist ...
show more
219.145.111.197 (CN/China/Shanxi/Fenyang/-/[AS4134 CHINANET-BACKBONE No.31,Jin-rong Street]), 5 distributed smtpauth attacks on account [stay] in the last 1200 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: 2022-10-31 05:40:15 login authenticator failed for (UK4inv) [219.145.111.197]: 535 Incorrect authentication data (set_id=stay)
2022-10-31 05:35:14 login authenticator failed for (RqrO9y) [219.145.111.253]: 535 Incorrect authentication data (set_id=stay)
2022-10-31 05:32:15 login authenticator failed for (IWrCRWl) [117.37.10.181]: 535 Incorrect authentication data (set_id=stay)
2022-10-31 05:33:41 login authenticator failed for (8fFTLeZGuZ) [117.37.11.237]: 535 Incorrect authentication data (set_id=stay)
2022-10-31 05:32:01 login authenticator failed for (p3ESggJ) [117.37.10.181]: 535 Incorrect authentication data (set_id=stay)
IP Addresses Blocked:
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2022-09-22 21:33:46
(3 years ago)
postfix-aggressive
Brute-Force
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: