This IP address has been reported a total of
268
times from
158 distinct
sources.
220.250.52.111 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Repeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed ...
show moreRepeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed authentication attempts from this IP across an extended period.
show less
sshd: Invalid user frappe from 220.250.52.111 port 32770
sshd: Invalid user admin from 220.250.52.11 ...
show moresshd: Invalid user frappe from 220.250.52.111 port 32770
sshd: Invalid user admin from 220.250.52.111 port 34976
show less
2026-06-12T08:38:23.570Z, an unauthorized access attempt was detected on port 22 (SSH) from source I ...
show more2026-06-12T08:38:23.570Z, an unauthorized access attempt was detected on port 22 (SSH) from source IP address 220.250.52.111.
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-06-12T06:12:24.948636+00:00 vpn01 sshd[3435943]: User root from 220.250.52.111 not allowed beca ...
show more2026-06-12T06:12:24.948636+00:00 vpn01 sshd[3435943]: User root from 220.250.52.111 not allowed because not listed in AllowUsers
2026-06-12T06:15:55.194523+00:00 vpn01 sshd[3436082]: Invalid user ftpuser from 220.250.52.111 port 49494
2026-06-12T06:16:39.023332+00:00 vpn01 sshd[3436114]: Invalid user adv from 220.250.52.111 port 49304
...
show less
2026-06-12T04:46:38.322505+02:00 fusco sshd-session[50447]: Invalid user es from 220.250.52.111 port ...
show more2026-06-12T04:46:38.322505+02:00 fusco sshd-session[50447]: Invalid user es from 220.250.52.111 port 41612
2026-06-12T04:46:38.324674+02:00 fusco sshd-session[50447]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.250.52.111
2026-06-12T04:46:40.279867+02:00 fusco sshd-session[50447]: Failed password for invalid user es from 220.250.52.111 port 41612 ssh2
...
show less
Cowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-12T00:08:08Z and 2026-06-1 ...
show moreCowrie Honeypot: 5 unauthorised SSH/Telnet login attempts between 2026-06-12T00:08:08Z and 2026-06-12T01:29:56Z
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: wizard, Pass: [REDACTED]
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: desktop, Pass: [REDACTED]
220.250.52.111 (CN/China/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Por ...
show more220.250.52.111 (CN/China/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 11 19:25:08 14995 sshd[16601]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.250.52.111 user=root
Jun 11 19:01:02 14995 sshd[3502]: Failed password for root from 43.133.61.254 port 49414 ssh2
Jun 11 19:18:22 14995 sshd[12925]: Failed password for root from 220.250.52.111 port 36342 ssh2
Jun 11 19:18:20 14995 sshd[12925]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.250.52.111 user=root
Jun 11 19:19:03 14995 sshd[13401]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=37.46.18.151 user=root
IP Addresses Blocked:
show less
Brute-Force
SSH
Anonymous
SSH brute force attempt. User: root, Pass: [REDACTED]
Jun 11 21:48:59 server1 sshd[420213]: Invalid user admin2 from 220.250.52.111 port 33564
Jun 11 21:5 ...
show moreJun 11 21:48:59 server1 sshd[420213]: Invalid user admin2 from 220.250.52.111 port 33564
Jun 11 21:58:19 server1 sshd[421521]: Invalid user user from 220.250.52.111 port 36928
Jun 11 21:59:06 server1 sshd[421635]: Invalid user oneadmin from 220.250.52.111 port 48902
...
show less
Brute-Force
SSH
Showing 1 to
15
of 268 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ