This IP address has been reported a total of
413
times from
165 distinct
sources.
31.141.249.54 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to log in to our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-09-16 14:59 to 2026-09-16 15:00 UTC | 1 session | 27 events | SSH (port 22)
Attack chain:
1. 1 credential attempt: deploy/u3$buyh8-n6!O$D
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/31.141.249.54.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
2026-09-10T10:10:30.047704+02:00 vps-49934a4d endlessh[3492766]: 2026-09-10T08:10:30.047Z ACCEPT hos ...
show more2026-09-10T10:10:30.047704+02:00 vps-49934a4d endlessh[3492766]: 2026-09-10T08:10:30.047Z ACCEPT host=::ffff:31.141.249.54 port=42701 fd=4 n=1/4096
...
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH honeypot detection (Endlessh tarpit, port 22). 3 probe(s) sustained for 1m total hold time. Cons ...
show moreSSH honeypot detection (Endlessh tarpit, port 22). 3 probe(s) sustained for 1m total hold time. Consistent with automated SSH scanning/brute-force. Reported by dotnetdork.dev security honeypot.
show less
2026-06-17T08:26:40.568822+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user hduser from 3 ...
show more2026-06-17T08:26:40.568822+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user hduser from 31.141.249.54 port 50806
2026-06-17T08:27:21.628656+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user vyos from 31.141.249.54 port 51713
2026-06-17T08:28:26.605544+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user jenkins from 31.141.249.54 port 53807
2026-06-17T08:28:53.985009+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user cloud from 31.141.249.54 port 54740
2026-06-17T08:29:19.084991+00:00 debian-4gb-hel1-2 18fe2893d46b[3158683]: Invalid user user1 from 31.141.249.54 port 55500
...
show less
2026-06-03T01:06:40.177418+02:00 vps-49934a4d endlessh[4012593]: 2026-06-02T23:06:40.175Z ACCEPT hos ...
show more2026-06-03T01:06:40.177418+02:00 vps-49934a4d endlessh[4012593]: 2026-06-02T23:06:40.175Z ACCEPT host=::ffff:31.141.249.54 port=50433 fd=4 n=1/4096
...
show less
2026-05-31T03:09:58.377286+00:00 Linux17 sshd[63704]: Invalid user postgres from 31.141.249.54 port ...
show more2026-05-31T03:09:58.377286+00:00 Linux17 sshd[63704]: Invalid user postgres from 31.141.249.54 port 54918
2026-05-31T03:10:00.878465+00:00 Linux17 sshd[63704]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=31.141.249.54
2026-05-31T03:10:02.871180+00:00 Linux17 sshd[63704]: Failed password for invalid user postgres from 31.141.249.54 port 54918 ssh2
2026-05-31T03:10:36.949732+00:00 Linux17 sshd[567]: Invalid user test from 31.141.249.54 port 55135
2026-05-31T03:10:40.161759+00:00 Linux17 sshd[567]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=31.141.249.54
2026-05-31T03:10:41.978049+00:00 Linux17 sshd[567]: Failed password for invalid user test from 31.141.249.54 port 55135 ssh2
2026-05-31T03:11:16.458746+00:00 Linux17 sshd[2452]: Invalid user dspace from 31.141.249.54 port 55364
2026-05-31T03:11:18.985903+00:00 Linux17 sshd[2452]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty
...
show less