This IP address has been reported a total of
273
times from
146 distinct
sources.
54.38.132.70 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Malicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: ...
show moreMalicious activity detected from this IP during SSH attempts. VPN: No, Datacenter: No, Organization: AS16276 OVH SAS, Region: Mazovia, Log: 2026-08-27T16:09:18.983327 02:00 Administracion sshd[398507]: Connection closed by authenticating user root 54.38.132.70 port 35772 [preauth], Abuse Score: 100, Total Reports: 268
show less
2026-08-28T00:08:07.903751+10:00 phosphor sshd-session[1569686]: Connection from 54.38.132.70 port 5 ...
show more2026-08-28T00:08:07.903751+10:00 phosphor sshd-session[1569686]: Connection from 54.38.132.70 port 56334 on 163.227.128.186 port 22 rdomain ""
2026-08-28T00:08:09.263320+10:00 phosphor sshd-session[1569686]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70 user=root
2026-08-28T00:08:10.545802+10:00 phosphor sshd-session[1569686]: Failed password for root from 54.38.132.70 port 56334 ssh2
...
show less
2026-08-27 08:56:22.008472-0500 localhost sshd-session[35503]: Failed password for root from 54.38. ...
show more2026-08-27 08:56:22.008472-0500 localhost sshd-session[35503]: Failed password for root from 54.38.132.70 port 50410 ssh2
show less
Aug 27 15:40:06 main-angler sshd[3338966]: Invalid user ubuntu from 54.38.132.70 port 60810
Aug 27 1 ...
show moreAug 27 15:40:06 main-angler sshd[3338966]: Invalid user ubuntu from 54.38.132.70 port 60810
Aug 27 15:40:08 main-angler sshd[3338966]: Failed password for invalid user ubuntu from 54.38.132.70 port 60810 ssh2
Aug 27 15:49:52 main-angler sshd[3349274]: Invalid user centos from 54.38.132.70 port 40254
...
show less
Multiple SSH login attempts from 54.38.132.70 targeting user(s): beta,token | Server Managed by Focu ...
show moreMultiple SSH login attempts from 54.38.132.70 targeting user(s): beta,token | Server Managed by Focusnic
show less
2026-08-27T13:46:38.779549+00:00 [host] sshd[138116]: Invalid user centos from 54.38.132.70 port 471 ...
show more2026-08-27T13:46:38.779549+00:00 [host] sshd[138116]: Invalid user centos from 54.38.132.70 port 47186
show less
2026-08-27T15:45:02.863515 yip.floofy.tech sshd-session[3655665]: Invalid user erwin from 54.38.132. ...
show more2026-08-27T15:45:02.863515 yip.floofy.tech sshd-session[3655665]: Invalid user erwin from 54.38.132.70 port 33804
2026-08-27T15:45:02.915565 yip.floofy.tech sshd-session[3655665]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70
2026-08-27T15:45:05.590613 yip.floofy.tech sshd-session[3655665]: Failed password for invalid user erwin from 54.38.132.70 port 33804 ssh2
...
show less
Aug 27 15:38:47 vmi174663 sshd[617248]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreAug 27 15:38:47 vmi174663 sshd[617248]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70
Aug 27 15:38:49 vmi174663 sshd[617248]: Failed password for invalid user erwin from 54.38.132.70 port 51132 ssh2
Aug 27 15:44:24 vmi174663 sshd[619010]: Invalid user beta from 54.38.132.70 port 52942
Aug 27 15:44:24 vmi174663 sshd[619010]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70
Aug 27 15:44:26 vmi174663 sshd[619010]: Failed password for invalid user beta from 54.38.132.70 port 52942 ssh2
...
show less
2026-08-27T14:39:45.423751+01:00 ozelot sshd-session[2583025]: pam_unix(sshd:auth): authentication f ...
show more2026-08-27T14:39:45.423751+01:00 ozelot sshd-session[2583025]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70
2026-08-27T14:39:47.053229+01:00 ozelot sshd-session[2583025]: Failed password for invalid user erwin from 54.38.132.70 port 34792 ssh2
2026-08-27T14:40:05.196340+01:00 ozelot sshd-session[2585456]: Invalid user ubuntu from 54.38.132.70 port 42714
show less
2026-08-27T17:29:01.552349+08:00 cowgl sshd[2113186]: Failed password for invalid user exchange from ...
show more2026-08-27T17:29:01.552349+08:00 cowgl sshd[2113186]: Failed password for invalid user exchange from 54.38.132.70 port 60190 ssh2
2026-08-27T17:29:01.765265+08:00 cowgl sshd[2113186]: Connection closed by invalid user exchange 54.38.132.70 port 60190 [preauth]
2026-08-27T21:39:51.916514+08:00 cowgl sshd[2741004]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70 user=root
2026-08-27T21:39:53.559237+08:00 cowgl sshd[2741004]: Failed password for root from 54.38.132.70 port 46222 ssh2
...
show less
Aug 27 15:22:59 srv-ubuntu-dev3 sshd[791993]: Connection closed by authenticating user root 54.38.13 ...
show moreAug 27 15:22:59 srv-ubuntu-dev3 sshd[791993]: Connection closed by authenticating user root 54.38.132.70 port 56490 [preauth]
Aug 27 15:32:13 srv-ubuntu-dev3 sshd[793210]: Invalid user centos from 54.38.132.70 port 46542
Aug 27 15:32:13 srv-ubuntu-dev3 sshd[793210]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=54.38.132.70
Aug 27 15:32:15 srv-ubuntu-dev3 sshd[793210]: Failed password for invalid user centos from 54.38.132.70 port 46542 ssh2
Aug 27 15:32:16 srv-ubuntu-dev3 sshd[793210]: Connection closed by invalid user centos 54.38.132.70 port 46542 [preauth]
...
show less
2026-08-27T13:11:27.719819+00:00 ubuntu sshd[3989951]: Invalid user ubuntu from 54.38.132.70 port 54 ...
show more2026-08-27T13:11:27.719819+00:00 ubuntu sshd[3989951]: Invalid user ubuntu from 54.38.132.70 port 54150
2026-08-27T13:29:00.387970+00:00 ubuntu sshd[3990195]: Invalid user centos from 54.38.132.70 port 33152
...
show less
Brute-Force
SSH
Showing 1 to
15
of 273 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ