This IP address has been reported a total of
35
times from
30 distinct
sources.
49.207.243.13 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-06-18T19:49:20.450203+00:00 mta sshd[398412]: pam_unix(sshd:auth): authentication failure; logn ...
show more2026-06-18T19:49:20.450203+00:00 mta sshd[398412]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13
2026-06-18T19:49:22.781483+00:00 mta sshd[398412]: Failed password for invalid user kat from 49.207.243.13 port 11524 ssh2
...
show less
Brute-Force
SSH
Anonymous
2026-06-18T22:21:01.225117+03:00 main sshd-session[3771025]: Disconnected from authenticating user r ...
show more2026-06-18T22:21:01.225117+03:00 main sshd-session[3771025]: Disconnected from authenticating user root 49.207.243.13 port 12938 [preauth]
2026-06-18T22:21:27.639675+03:00 main sshd-session[3771143]: Invalid user jayden from 49.207.243.13 port 11647
2026-06-18T22:21:27.646132+03:00 main sshd-session[3771143]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13
2026-06-18T22:21:30.258647+03:00 main sshd-session[3771143]: Failed password for invalid user jayden from 49.207.243.13 port 11647 ssh2
2026-06-18T22:21:30.742062+03:00 main sshd-session[3771143]: Disconnected from invalid user jayden 49.207.243.13 port 11647 [preauth]
...
show less
2026-06-18T19:02:50.953702+00:00 kocer-main-webserver sshd[945563]: Disconnected from authenticating ...
show more2026-06-18T19:02:50.953702+00:00 kocer-main-webserver sshd[945563]: Disconnected from authenticating user root 49.207.243.13 port 12575 [preauth]
2026-06-18T19:09:04.744001+00:00 kocer-main-webserver sshd[946280]: Invalid user ftpuser from 49.207.243.13 port 12054
2026-06-18T19:09:04.987278+00:00 kocer-main-webserver sshd[946280]: Disconnected from invalid user ftpuser 49.207.243.13 port 12054 [preauth]
...
show less
2026-06-18T20:46:26.160040+02:00 axisverse sshd-session[522071]: Invalid user pbi from 49.207.243.13 ...
show more2026-06-18T20:46:26.160040+02:00 axisverse sshd-session[522071]: Invalid user pbi from 49.207.243.13 port 12269
2026-06-18T20:49:58.790645+02:00 axisverse sshd-session[530067]: Invalid user unsubscribe from 49.207.243.13 port 12104
2026-06-18T20:51:01.000773+02:00 axisverse sshd-session[533358]: Invalid user proposal from 49.207.243.13 port 11994
...
show less
Jun 18 18:14:40 mail sshd[660257]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid= ...
show moreJun 18 18:14:40 mail sshd[660257]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13
Jun 18 18:14:42 mail sshd[660257]: Failed password for invalid user student4 from 49.207.243.13 port 12335 ssh2
Jun 18 18:16:10 mail sshd[660273]: Invalid user rajesh from 49.207.243.13 port 11550
...
show less
Hacking
Brute-Force
SSH
Anonymous
SSH Brute Force (3 attempts). Evidence: sshd[2144777]: Invalid user student4 from 49.207.243.13 port ...
show moreSSH Brute Force (3 attempts). Evidence: sshd[2144777]: Invalid user student4 from 49.207.243.13 port 12751;sshd[2144777]: Disconnected from invalid user student4 49.207.243.13 port 12751 [preauth]
show less
SSH Brute force: 11 attempts were recorded from 49.207.243.13
2026-06-18T19:49:26+02:00 Connection f ...
show moreSSH Brute force: 11 attempts were recorded from 49.207.243.13
2026-06-18T19:49:26+02:00 Connection from 49.207.243.13 port 12727 on <redacted> port 22 rdomain ""
2026-06-18T19:49:27+02:00 Invalid user linuxbrew from 49.207.243.13 port 12727
2026-06-18T19:49:27+02:00 Disconnected from invalid user linuxbrew 49.207.243.13 port 12727 [preauth]
2026-06-18T19:50:49+02:00 Connection from 49.207.243.13 port 11692 on <redacted> port 22 rdomain ""
2026-06-18T19:50:50+02:00 Invalid user op from 49.207.243.13 port 11692
2026-06-18T19:50:50+02:00 Disconnected from invalid user op 49.207.243.13 port 11692 [preauth]
2026-06-18T19:53:16+02:00 Connection from 49.207.243.13 port 12664 on <redacted> port 22 rdomain ""
2026-06-18T19:53:17+02:00 Invalid user vmail from 49.207.243.13 port 12664
2026-06-18T19:53:17+02:00 Disconnected from invalid user vmail 49.207.243.13 port 12664 [preauth]
2026-06-18T19:53:
show less
2026-06-18T19:40:19.815226+02:00 axisverse sshd-session[360471]: Invalid user szczecin from 49.207.2 ...
show more2026-06-18T19:40:19.815226+02:00 axisverse sshd-session[360471]: Invalid user szczecin from 49.207.243.13 port 13338
2026-06-18T19:44:27.051552+02:00 axisverse sshd-session[370489]: Invalid user beagle from 49.207.243.13 port 12338
2026-06-18T19:44:50.555025+02:00 axisverse sshd-session[371349]: Invalid user zt from 49.207.243.13 port 11744
...
show less
(sshd) Failed SSH login from 49.207.243.13 (IN/India/broadband.actcorp.in): 5 in the last 3600 secs; ...
show more(sshd) Failed SSH login from 49.207.243.13 (IN/India/broadband.actcorp.in): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 18 12:27:46 15663 sshd[20641]: Invalid user ubuntu from 49.207.243.13 port 13087
Jun 18 12:27:48 15663 sshd[20641]: Failed password for invalid user ubuntu from 49.207.243.13 port 13087 ssh2
Jun 18 12:35:30 15663 sshd[24838]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13 user=root
Jun 18 12:35:32 15663 sshd[24838]: Failed password for root from 49.207.243.13 port 13365 ssh2
Jun 18 12:35:42 15663 sshd[24894]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13 user=root
show less
Jun 18 13:54:47 ws22vmsma01 sshd[11718]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreJun 18 13:54:47 ws22vmsma01 sshd[11718]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13
Jun 18 13:54:49 ws22vmsma01 sshd[11718]: Failed password for invalid user peachy from 49.207.243.13 port 12059 ssh2
...
show less
SSH brute force evidence on vps-c210724c. Reason: Fail2ban ban observed. User=n/a Port=22. Evidence ...
show moreSSH brute force evidence on vps-c210724c. Reason: Fail2ban ban observed. User=n/a Port=22. Evidence lines:
2026-06-18T16:45:12.998201+00:00 vps-c210724c sshd-session[283392]: Invalid user islam from 49.207.243.13 port 13139
2026-06-18T16:45:15.010730+00:00 vps-c210724c sshd-session[283392]: Failed password for invalid user islam from 49.207.243.13 port 13139 ssh2
2026-06-18T16:48:42.664767+00:00 vps-c210724c sshd-session[283720]: Invalid user cmsadmin from 49.207.243.13 port 13230
show less
2026-06-18T16:34:07.323061+00:00 edge-hur-fmt01.int.pdx.net.uk sshd[1093004]: Invalid user rescue fr ...
show more2026-06-18T16:34:07.323061+00:00 edge-hur-fmt01.int.pdx.net.uk sshd[1093004]: Invalid user rescue from 49.207.243.13 port 12057
2026-06-18T16:35:47.243435+00:00 edge-hur-fmt01.int.pdx.net.uk sshd[1093147]: Invalid user deploy from 49.207.243.13 port 12141
2026-06-18T16:39:48.733871+00:00 edge-hur-fmt01.int.pdx.net.uk sshd[1093508]: Invalid user admin from 49.207.243.13 port 12751
...
show less
Brute-Force
SSH
Anonymous
(sshd) Failed SSH login from 49.207.243.13 (IN/India/broadband.actcorp.in): 5 in the last 3600 secs; ...
show more(sshd) Failed SSH login from 49.207.243.13 (IN/India/broadband.actcorp.in): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: Jun 19 02:32:19 syd2 sshd[906528]: Invalid user rescue from 49.207.243.13 port 12579
Jun 19 02:32:21 syd2 sshd[906528]: Failed password for invalid user rescue from 49.207.243.13 port 12579 ssh2
Jun 19 02:37:05 syd2 sshd[907019]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=49.207.243.13 user=root
Jun 19 02:37:07 syd2 sshd[907019]: Failed password for root from 49.207.243.13 port 13395 ssh2
Jun 19 02:37:57 syd2 sshd[907094]: Invalid user morris from 49.207.243.13 port 11427
show less