This IP address has been reported a total of
75
times from
69 distinct
sources.
220.85.210.200 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
This IP address carried out 5 SSH credential attack (attempts) on 23-07-2026. For more information o ...
show moreThis IP address carried out 5 SSH credential attack (attempts) on 23-07-2026. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
[rede-44-49] (sshd) Failed SSH login from 220.85.210.200 (KR/South Korea/-): 5 in the last 3600 secs ...
show more[rede-44-49] (sshd) Failed SSH login from 220.85.210.200 (KR/South Korea/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Jul 23 21:46:00 sshd[14317]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.85.210.200 user=[USERNAME]
Jul 23 21:46:02 sshd[14317]: Failed password for [USERNAME] from 220.85.210.200 port 49536 ssh2
Jul 23 21:46:05 sshd[14317]: Failed password for [USERNAME] from 220.85.210.200 port 49536 ssh2
Jul 23 21:46:08 sshd[14317]: Failed password for [USERNAME] from 220.85.210.200 port 49536 ssh2
Jul 23 21:46:10 sshd[14317]: Failed password for [USERNAME] fro
show less
Jul 24 02:28:45 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2 ...
show moreJul 24 02:28:45 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2
Jul 24 02:28:49 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2
Jul 24 02:28:52 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2
Jul 24 02:28:55 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2
Jul 24 02:28:58 vmi174663 sshd[974402]: Failed password for root from 220.85.210.200 port 40186 ssh2
...
show less
Jul 23 18:14:27 b146-66 sshd[153198]: Failed password for root from 220.85.210.200 port 51766 ssh2
J ...
show moreJul 23 18:14:27 b146-66 sshd[153198]: Failed password for root from 220.85.210.200 port 51766 ssh2
Jul 23 18:14:31 b146-66 sshd[153198]: Failed password for root from 220.85.210.200 port 51766 ssh2
Jul 23 18:14:34 b146-66 sshd[153198]: Failed password for root from 220.85.210.200 port 51766 ssh2
...
show less
2026-07-24T05:23:24.045707+05:30 ittifakordusu sshd-session[3832697]: Failed password for root from ...
show more2026-07-24T05:23:24.045707+05:30 ittifakordusu sshd-session[3832697]: Failed password for root from 220.85.210.200 port 46198 ssh2
2026-07-24T05:23:26.233341+05:30 ittifakordusu sshd-session[3832697]: Failed password for root from 220.85.210.200 port 46198 ssh2
2026-07-24T05:23:29.883248+05:30 ittifakordusu sshd-session[3832697]: Failed password for root from 220.85.210.200 port 46198 ssh2
...
show less
Report 2570044 with IP 3617611 for SSH brute-force attack by source 3612269 via ssh-honeypot/0.2.0+h ...
show moreReport 2570044 with IP 3617611 for SSH brute-force attack by source 3612269 via ssh-honeypot/0.2.0+http
show less
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_ssh. So ...
show moreDetected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_ssh. Sources: honeypot. First seen: 2026-07-23. Risk score: 100/100.
show less
2026-07-24T05:40:29.408397+08:00 vmi996132.contaboserver.net sshd[1776416]: Failed password for root ...
show more2026-07-24T05:40:29.408397+08:00 vmi996132.contaboserver.net sshd[1776416]: Failed password for root from 220.85.210.200 port 48490 ssh2
2026-07-24T05:40:32.377633+08:00 vmi996132.contaboserver.net sshd[1776416]: Failed password for root from 220.85.210.200 port 48490 ssh2
2026-07-24T05:40:34.966536+08:00 vmi996132.contaboserver.net sshd[1776416]: Failed password for root from 220.85.210.200 port 48490 ssh2
...
show less
2026-07-23T13:23:02.730524-07:00 debian sshd-session[319424]: error: maximum authentication attempts ...
show more2026-07-23T13:23:02.730524-07:00 debian sshd-session[319424]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 52668 ssh2 [preauth]
2026-07-23T13:23:05.653841-07:00 debian sshd-session[319426]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 53286 ssh2 [preauth]
2026-07-23T13:23:08.713507-07:00 debian sshd-session[319431]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 53964 ssh2 [preauth]
2026-07-23T13:23:12.453296-07:00 debian sshd-session[319435]: Invalid user admin from 220.85.210.200 port 55074
2026-07-23T13:23:13.483604-07:00 debian sshd-session[319435]: error: maximum authentication attempts exceeded for invalid user admin from 220.85.210.200 port 55074 ssh2 [preauth]
...
show less
2026-07-23T19:59:30.834624+00:00 lord-kerry-app sshd[294259]: error: maximum authentication attempts ...
show more2026-07-23T19:59:30.834624+00:00 lord-kerry-app sshd[294259]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 33486 ssh2 [preauth]
2026-07-23T19:59:34.151454+00:00 lord-kerry-app sshd[294261]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 34362 ssh2 [preauth]
2026-07-23T19:59:37.217713+00:00 lord-kerry-app sshd[294263]: error: maximum authentication attempts exceeded for root from 220.85.210.200 port 35000 ssh2 [preauth]
...
show less
2026-07-23T21:52:01.678050+02:00 ns3006402 sshd[4005536]: Failed password for root from 220.85.210.2 ...
show more2026-07-23T21:52:01.678050+02:00 ns3006402 sshd[4005536]: Failed password for root from 220.85.210.200 port 58460 ssh2
2026-07-23T21:52:05.881980+02:00 ns3006402 sshd[4005536]: Failed password for root from 220.85.210.200 port 58460 ssh2
2026-07-23T21:52:08.719915+02:00 ns3006402 sshd[4005536]: Failed password for root from 220.85.210.200 port 58460 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 75 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ