This IP address has been reported a total of
15
times from
12 distinct
sources.
38.181.42.232 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot bot from US: 2 SSH login attempts; 2 commands executed; first 2026-06-14 13:14:06, last 202 ...
show moreHoneypot bot from US: 2 SSH login attempts; 2 commands executed; first 2026-06-14 13:14:06, last 2026-06-14 13:14:41
show less
(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; ...
show more(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 14 09:22:44 21257 sshd[24325]: Did not receive identification string from 38.181.42.232 port 57232
Jun 14 09:23:05 21257 sshd[24655]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 09:23:06 21257 sshd[24655]: Failed password for root from 38.181.42.232 port 53018 ssh2
Jun 14 09:23:12 21257 sshd[24681]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 09:23:14 21257 sshd[24681]: Failed password for root from 38.181.42.232 port 53044 ssh2
show less
(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; ...
show more(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 14 14:06:50 22574 sshd[23355]: Did not receive identification string from 38.181.42.232 port 53306
Jun 14 14:06:52 22574 sshd[23356]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 14:06:54 22574 sshd[23356]: Failed password for root from 38.181.42.232 port 53322 ssh2
Jun 14 14:07:04 22574 sshd[23444]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 14:07:06 22574 sshd[23444]: Failed password for root from 38.181.42.232 port 51206 ssh2
show less
2026-06-14T13:48:54.898543+00:00 Debian sshd[826072]: error: kex_exchange_identification: Connection ...
show more2026-06-14T13:48:54.898543+00:00 Debian sshd[826072]: error: kex_exchange_identification: Connection closed by remote host
2026-06-14T13:48:54.899732+00:00 Debian sshd[826072]: Connection closed by 38.181.42.232 port 60136
...
show less
(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; ...
show more(sshd) Failed SSH login from 38.181.42.232 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 14 08:44:12 17538 sshd[3210]: Did not receive identification string from 38.181.42.232 port 39702
Jun 14 08:44:31 17538 sshd[3262]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 08:44:33 17538 sshd[3262]: Failed password for root from 38.181.42.232 port 54116 ssh2
Jun 14 08:44:43 17538 sshd[3353]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 08:44:45 17538 sshd[3353]: Failed password for root from 38.181.42.232 port 58180 ssh2
show less
Report 2462990 with IP 3510557 for SSH brute-force attack by source 3505215 via ssh-honeypot/0.2.1+h ...
show moreReport 2462990 with IP 3510557 for SSH brute-force attack by source 3505215 via ssh-honeypot/0.2.1+http
show less
38.181.42.232 (US/United States/-), 5 distributed sshd attacks on account [root] in the last 3600 se ...
show more38.181.42.232 (US/United States/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 14 06:15:00 14967 sshd[32113]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 05:48:19 14967 sshd[29553]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=154.116.254.157 user=root
Jun 14 05:48:20 14967 sshd[29553]: Failed password for root from 154.116.254.157 port 46010 ssh2
Jun 14 06:00:33 14967 sshd[30712]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=99.144.123.156 user=root
Jun 14 06:00:35 14967 sshd[30712]: Failed password for root from 99.144.123.156 port 37596 ssh2
IP Addresses Blocked:
show less
Jun 14 13:10:15 mail6 sshd-session[1995299]: Failed password for invalid user root from 38.181.42.23 ...
show moreJun 14 13:10:15 mail6 sshd-session[1995299]: Failed password for invalid user root from 38.181.42.232 port 44002 ssh2
Jun 14 13:10:28 mail6 sshd-session[1995408]: User root from 38.181.42.232 not allowed because not listed in AllowUsers
Jun 14 13:10:28 mail6 sshd-session[1995408]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 13:10:30 mail6 sshd-session[1995408]: Failed password for invalid user root from 38.181.42.232 port 59674 ssh2
Jun 14 13:10:39 mail6 sshd-session[1995471]: User root from 38.181.42.232 not allowed because not listed in AllowUsers
...
show less
2026-06-14T19:15:55.149571+09:00 no2 sshd[3056153]: Connection closed by authenticating user root 38 ...
show more2026-06-14T19:15:55.149571+09:00 no2 sshd[3056153]: Connection closed by authenticating user root 38.181.42.232 port 57404 [preauth]
...
show less
Jun 14 08:37:46 madrants sshd[3232816]: Failed password for root from 38.181.42.232 port 41898 ssh2
...
show moreJun 14 08:37:46 madrants sshd[3232816]: Failed password for root from 38.181.42.232 port 41898 ssh2
Jun 14 08:37:48 madrants sshd[3232818]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
Jun 14 08:37:49 madrants sshd[3232818]: Failed password for root from 38.181.42.232 port 41910 ssh2
...
show less
2026-06-14T08:27:33.404608+00:00 NBG-VS01-WebServer sshd-session[1152608]: Failed password for root ...
show more2026-06-14T08:27:33.404608+00:00 NBG-VS01-WebServer sshd-session[1152608]: Failed password for root from 38.181.42.232 port 45378 ssh2
2026-06-14T08:27:35.911401+00:00 NBG-VS01-WebServer sshd-session[1152612]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.181.42.232 user=root
2026-06-14T08:27:37.765540+00:00 NBG-VS01-WebServer sshd-session[1152612]: Failed password for root from 38.181.42.232 port 49990 ssh2
...
show less
Brute-Force
SSH
Showing 1 to
15
of 15 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ