This IP address has been reported a total of
14
times from
14 distinct
sources.
38.242.133.44 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-09T05:26:06.000840+00:00 helium sshd-session[549774]: Connection closed by authenticating us ...
show more2026-06-09T05:26:06.000840+00:00 helium sshd-session[549774]: Connection closed by authenticating user root 38.242.133.44 port 57116 [preauth]
2026-06-09T05:39:32.789264+00:00 helium sshd-session[551634]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.242.133.44 user=root
2026-06-09T05:39:35.639064+00:00 helium sshd-session[551634]: Failed password for root from 38.242.133.44 port 37152 ssh2
...
show less
Jun 9 06:58:53 ***** sshd[3580341]: User root from 38.242.133.44 not allowed because not listed in ...
show moreJun 9 06:58:53 ***** sshd[3580341]: User root from 38.242.133.44 not allowed because not listed in AllowUsers
show less
2026-06-09T01:59:31.379946+00:00 sshd[52022]: pam_unix(sshd:auth): authentication failure; logname= ...
show more2026-06-09T01:59:31.379946+00:00 sshd[52022]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.242.133.44 user=root
2026-06-09T01:59:34.076835+00:00 sshd[52022]: Failed password for root from 38.242.133.44 port 47994 ssh2
...
show less
Brute-Force
SSH
Anonymous
38.242.133.44 (DE/Germany/vmi2873803.contaboserver.net), 5 distributed sshd attacks on account [root ...
show more38.242.133.44 (DE/Germany/vmi2873803.contaboserver.net), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: Jun 9 11:49:47 syd2 sshd[2108193]: Failed password for root from 79.11.39.204 port 59262 ssh2
Jun 9 11:50:43 syd2 sshd[2108339]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.20.144.141 user=root
Jun 9 11:48:46 syd2 sshd[2108111]: Failed password for root from 38.242.133.44 port 55512 ssh2
Jun 9 11:50:14 syd2 sshd[2108286]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=45.166.144.212 user=root
Jun 9 11:50:16 syd2 sshd[2108286]: Failed password for root from 45.166.144.212 port 36224 ssh2
IP Addresses Blocked:
79.11.39.204 (IT/Italy/host-79-11-39-204.business.telecomitalia.it)
103.20.144.141 (VN/Vietnam/-)
show less
Port Scan
Anonymous
Automated Report: Fail2Ban block triggered by sshd jail.
Jun 8 19:29:09 web sshd[127663]: User root from 38.242.133.44 not allowed because none of user's gr ...
show moreJun 8 19:29:09 web sshd[127663]: User root from 38.242.133.44 not allowed because none of user's groups are listed in AllowGroups
Jun 8 19:29:09 web sshd[127663]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.242.133.44 user=root
Jun 8 19:29:13 web sshd[127663]: Failed password for invalid user root from 38.242.133.44 port 32802 ssh2
...
show less
38.242.133.44 (DE/Germany/vmi2873803.contaboserver.net), 5 distributed sshd attacks on account [tomc ...
show more38.242.133.44 (DE/Germany/vmi2873803.contaboserver.net), 5 distributed sshd attacks on account [tomcat] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 8 18:31:01 15145 sshd[2450]: Invalid user tomcat from 45.166.144.212 port 58670
Jun 8 18:31:03 15145 sshd[2450]: Failed password for invalid user tomcat from 45.166.144.212 port 58670 ssh2
Jun 8 18:29:31 15145 sshd[1810]: Invalid user tomcat from 23.88.96.39 port 40486
Jun 8 18:29:32 15145 sshd[1810]: Failed password for invalid user tomcat from 23.88.96.39 port 40486 ssh2
Jun 8 18:31:31 15145 sshd[2787]: Invalid user tomcat from 38.242.133.44 port 53294
IP Addresses Blocked:
45.166.144.212 (CL/Chile/-)
23.88.96.39 (DE/Germany/static.39.96.88.23.clients.your-server.de)
show less