This IP was reported 24 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
24
times from
21 distinct
sources.
2a00:f940:2:4:2::21f7 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-08-23T01:16:36.234908+08:00 cowgl sshd[2058693]: Connection closed by invalid user wallet 2a00: ...
show more2026-08-23T01:16:36.234908+08:00 cowgl sshd[2058693]: Connection closed by invalid user wallet 2a00:f940:2:4:2::21f7 port 43832 [preauth]
2026-08-23T02:34:52.610735+08:00 cowgl sshd[2249305]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7 user=root
2026-08-23T02:34:55.217216+08:00 cowgl sshd[2249305]: Failed password for root from 2a00:f940:2:4:2::21f7 port 56146 ssh2
2026-08-23T02:34:56.466956+08:00 cowgl sshd[2249305]: Connection closed by authenticating user root 2a00:f940:2:4:2::21f7 port 56146 [preauth]
...
show less
2026-08-22T20:15:14.956905+02:00 hosting.defencegeeks.net sshd-session[3204382]: Invalid user %first ...
show more2026-08-22T20:15:14.956905+02:00 hosting.defencegeeks.net sshd-session[3204382]: Invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 35424
2026-08-22T20:15:15.207573+02:00 hosting.defencegeeks.net sshd-session[3204382]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7
2026-08-22T20:15:16.902784+02:00 hosting.defencegeeks.net sshd-session[3204382]: Failed password for invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 35424 ssh2
2026-08-22T20:22:27.291811+02:00 hosting.defencegeeks.net sshd-session[3210423]: Invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 50804
2026-08-22T20:22:27.620890+02:00 hosting.defencegeeks.net sshd-session[3210423]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7
2026-08-22T20:22:29.383135+02:00 hosting.defencegeeks.net sshd-session[3210423]: Failed password for invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 508
...
show less
2026-08-22T20:00:31.168608+02:00 ns3124905 sshd-session[2543750]: Invalid user %firstword% from 2a00 ...
show more2026-08-22T20:00:31.168608+02:00 ns3124905 sshd-session[2543750]: Invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 60728
2026-08-22T20:00:31.449011+02:00 ns3124905 sshd-session[2543750]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7
2026-08-22T20:00:33.897222+02:00 ns3124905 sshd-session[2543750]: Failed password for invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 60728 ssh2
...
show less
2026-08-22T11:18:05.737217-05:00 lab.bjmgeek.science sshd-session[2858190]: Invalid user test from 2 ...
show more2026-08-22T11:18:05.737217-05:00 lab.bjmgeek.science sshd-session[2858190]: Invalid user test from 2a00:f940:2:4:2::21f7 port 33024
2026-08-22T11:18:05.957566-05:00 lab.bjmgeek.science sshd-session[2858190]: Connection closed by invalid user test 2a00:f940:2:4:2::21f7 port 33024 [preauth]
2026-08-22T12:45:12.967566-05:00 lab.bjmgeek.science sshd-session[2858533]: Invalid user %firstword% from 2a00:f940:2:4:2::21f7 port 39748
...
show less
Aug 22 17:44:57 [host] sshd[268416]: Invalid user wallet from 2a00:f940:2:4:2::21f7 port 45264
Aug 2 ...
show moreAug 22 17:44:57 [host] sshd[268416]: Invalid user wallet from 2a00:f940:2:4:2::21f7 port 45264
Aug 22 17:45:00 [host] sshd[268416]: Failed password for invalid user wallet from 2a00:f940:2:4:2::21f7 port 45264 ssh2
Aug 22 18:56:27 [host] sshd[298008]: Invalid user wallet from 2a00:f940:2:4:2::21f7 port 54578
Aug 22 19:24:38 [host] sshd[309014]: Failed password for [user] from 2a00:f940:2:4:2::21f7 port 41176 ssh2
Aug 22 19:38:06 [host] sshd[314062]: Failed password for [user] from 2a00:f940:2:4:2::21f7 port 49204 ssh2
Aug 22 17:44:58 [host] sshd[268416]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7
Aug 22 17:45:00 [host] sshd[268416]: Connection closed by invalid user wallet 2a00:f940:2:4:2::21f7 port 45264 [preauth]
Aug 22 18:25:54 [host] sshd[286244]: Unable to negotiate with 2a00:f940:2:4:2::21f7 port 36434: no matching key exchange method found. Their offer: diffie-hellman-group14-sha256,diffie-hellman-group-exchange
show less
2026-08-22T17:58:23.124604+02:00 s0 sshd[3074626]: Failed password for invalid user test from 2a00:f ...
show more2026-08-22T17:58:23.124604+02:00 s0 sshd[3074626]: Failed password for invalid user test from 2a00:f940:2:4:2::21f7 port 57320 ssh2
2026-08-22T19:24:43.444018+02:00 s0 sshd[3086924]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a00:f940:2:4:2::21f7 user=root
2026-08-22T19:24:44.892428+02:00 s0 sshd[3086924]: Failed password for root from 2a00:f940:2:4:2::21f7 port 57664 ssh2
...
show less
2026-08-23T02:58:19.501182+10:00 phosphor sshd-session[1042651]: Invalid user wallet from 2a00:f940: ...
show more2026-08-23T02:58:19.501182+10:00 phosphor sshd-session[1042651]: Invalid user wallet from 2a00:f940:2:4:2::21f7 port 60070
2026-08-23T02:58:23.612668+10:00 phosphor sshd-session[1042651]: error: PAM: Authentication failure for illegal user wallet from 2a00:f940:2:4:2::21f7
2026-08-23T02:58:23.613076+10:00 phosphor sshd-session[1042651]: Failed keyboard-interactive/pam for invalid user wallet from 2a00:f940:2:4:2::21f7 port 60070 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 24 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ